zendesk-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (Zendesk tickets, user profiles, and organization details) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The agent retrieves external content using
ZENDESK_LIST_ZENDESK_TICKETS,ZENDESK_GET_ZENDESK_TICKET_BY_ID, andZENDESK_SEARCH_ZENDESK_USERSas described inSKILL.md. - Boundary markers: There are no explicit instructions or delimiters defined to isolate external data from the agent's instructions.
- Capability inventory: The skill has extensive write and delete capabilities, including
ZENDESK_CREATE_ZENDESK_TICKET,ZENDESK_UPDATE_ZENDESK_TICKET,ZENDESK_REPLY_ZENDESK_TICKET, andZENDESK_DELETE_ZENDESK_TICKET. - Sanitization: No content sanitization or validation protocols are mentioned for data retrieved from the Zendesk API.
- [EXTERNAL_DOWNLOADS]: The skill references external infrastructure to provide its core toolkit functionality.
- Fetches tool schemas and manages authentication via the Rube MCP server at
https://rube.app/mcp. - References toolkit documentation and resources hosted at
https://composio.dev/toolkits/zendesk.
Audit Metadata