skills/ericrisco/rsc-harness/zapier/Gen Agent Trust Hub

zapier

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process content from external SaaS applications which may contain malicious instructions hidden by third parties.
  • Ingestion points: Data is brought into the agent's context through tools like execute_zapier_read_action (found in SKILL.md and references/zapier-mcp-tools.md), which can fetch arbitrary content from apps like Gmail or Slack.
  • Boundary markers: The skill documentation includes a mandatory "Write-safety / irreversibility rule" in SKILL.md that requires the agent to show the user the exact payload and wait for manual approval before performing write actions.
  • Capability inventory: The skill possesses the capability to perform actions with real-world side effects (e.g., sending emails, creating CRM records) via the execute_zapier_write_action tool described in SKILL.md.
  • Sanitization: There are no explicit instructions or mechanisms defined within the skill to sanitize or filter the content retrieved from external tools before it is interpreted by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — zapier