helpdesk-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve and process support tickets which may contain untrusted data.
- Ingestion points: Support ticket content and metadata retrieved via the
HELPDESK_LIST_TICKETStool inSKILL.md. - Boundary markers: The instructions do not specify any delimiters (such as XML tags or triple backticks) or "ignore instructions" warnings to separate ticket content from agent commands.
- Capability inventory: The skill uses tools to list tickets, views, canned responses, and custom fields within the HelpDesk silo.
- Sanitization: There are no instructions provided for sanitizing, escaping, or filtering the external ticket content before it is interpolated into the agent's context.
- [EXTERNAL_DOWNLOADS]: The skill references and connects to the Rube MCP server at
https://rube.app/mcp. This is a well-known service for managing toolkits and does not involve the download of untrusted scripts or executables. - [COMMAND_EXECUTION]: No suspicious command-line execution patterns were detected; the skill relies entirely on structured MCP tool calls.
Audit Metadata