helpdesk-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve and process support tickets which may contain untrusted data.
  • Ingestion points: Support ticket content and metadata retrieved via the HELPDESK_LIST_TICKETS tool in SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters (such as XML tags or triple backticks) or "ignore instructions" warnings to separate ticket content from agent commands.
  • Capability inventory: The skill uses tools to list tickets, views, canned responses, and custom fields within the HelpDesk silo.
  • Sanitization: There are no instructions provided for sanitizing, escaping, or filtering the external ticket content before it is interpolated into the agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill references and connects to the Rube MCP server at https://rube.app/mcp. This is a well-known service for managing toolkits and does not involve the download of untrusted scripts or executables.
  • [COMMAND_EXECUTION]: No suspicious command-line execution patterns were detected; the skill relies entirely on structured MCP tool calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:49 PM