managing-freshservice

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a core helper function fs_api that executes shell commands via curl to interact with the Freshservice API. It also utilizes jq and column for parsing and formatting the returned data.
  • [DATA_EXFILTRATION]: The skill performs network operations to freshservice.com using the curl utility. Authentication is correctly managed through environment variables (FRESHSERVICE_API_KEY), ensuring secrets are not hardcoded or exposed in logs.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes data from an external platform (Freshservice tickets, assets, and CMDB items) which may contain user-controllable text.
  • Ingestion points: API GET requests in SKILL.md for tickets, assets, changes, and CMDB items.
  • Boundary markers: None implemented for processed text.
  • Capability inventory: Network access via curl, local processing via jq and column (SKILL.md).
  • Sanitization: None; data is piped directly into processing utilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:28 AM
Security Audit — agent-trust-hub — managing-freshservice