zendesk-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (Zendesk tickets, user profiles, and organization details) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The agent retrieves external content using ZENDESK_LIST_ZENDESK_TICKETS, ZENDESK_GET_ZENDESK_TICKET_BY_ID, and ZENDESK_SEARCH_ZENDESK_USERS as described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate external data from the agent's instructions.
  • Capability inventory: The skill has extensive write and delete capabilities, including ZENDESK_CREATE_ZENDESK_TICKET, ZENDESK_UPDATE_ZENDESK_TICKET, ZENDESK_REPLY_ZENDESK_TICKET, and ZENDESK_DELETE_ZENDESK_TICKET.
  • Sanitization: No content sanitization or validation protocols are mentioned for data retrieved from the Zendesk API.
  • [EXTERNAL_DOWNLOADS]: The skill references external infrastructure to provide its core toolkit functionality.
  • Fetches tool schemas and manages authentication via the Rube MCP server at https://rube.app/mcp.
  • References toolkit documentation and resources hosted at https://composio.dev/toolkits/zendesk.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:50 PM