box-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing external content from Box storage.
  • Ingestion points: The skill reads untrusted data through tools like BOX_SEARCH_FOR_CONTENT, BOX_LIST_ITEMS_IN_FOLDER, and BOX_GET_FILE_INFORMATION (referenced in SKILL.md).
  • Boundary markers: There are no instructions for the agent to treat external content as data only or to ignore any embedded instructions, which could allow malicious content to influence agent behavior.
  • Capability inventory: The skill possesses high-impact capabilities including BOX_UPLOAD_FILE, BOX_DELETE_FOLDER, BOX_UPDATE_COLLABORATION, and BOX_CANCEL_BOX_SIGN_REQUEST (referenced in SKILL.md).
  • Sanitization: No evidence of sanitization or validation of the content retrieved from Box was found.
  • [EXTERNAL_DOWNLOADS]: The skill requires the configuration of an external, third-party MCP server to operate.
  • Evidence: The setup instructions in SKILL.md direct the user to add https://rube.app/mcp as an MCP server endpoint.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:51 PM