box-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing external content from Box storage.
- Ingestion points: The skill reads untrusted data through tools like
BOX_SEARCH_FOR_CONTENT,BOX_LIST_ITEMS_IN_FOLDER, andBOX_GET_FILE_INFORMATION(referenced in SKILL.md). - Boundary markers: There are no instructions for the agent to treat external content as data only or to ignore any embedded instructions, which could allow malicious content to influence agent behavior.
- Capability inventory: The skill possesses high-impact capabilities including
BOX_UPLOAD_FILE,BOX_DELETE_FOLDER,BOX_UPDATE_COLLABORATION, andBOX_CANCEL_BOX_SIGN_REQUEST(referenced in SKILL.md). - Sanitization: No evidence of sanitization or validation of the content retrieved from Box was found.
- [EXTERNAL_DOWNLOADS]: The skill requires the configuration of an external, third-party MCP server to operate.
- Evidence: The setup instructions in SKILL.md direct the user to add
https://rube.app/mcpas an MCP server endpoint.
Audit Metadata