zapier
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process content from external SaaS applications which may contain malicious instructions hidden by third parties.
- Ingestion points: Data is brought into the agent's context through tools like
execute_zapier_read_action(found inSKILL.mdandreferences/zapier-mcp-tools.md), which can fetch arbitrary content from apps like Gmail or Slack. - Boundary markers: The skill documentation includes a mandatory "Write-safety / irreversibility rule" in
SKILL.mdthat requires the agent to show the user the exact payload and wait for manual approval before performing write actions. - Capability inventory: The skill possesses the capability to perform actions with real-world side effects (e.g., sending emails, creating CRM records) via the
execute_zapier_write_actiontool described inSKILL.md. - Sanitization: There are no explicit instructions or mechanisms defined within the skill to sanitize or filter the content retrieved from external tools before it is interpreted by the agent.
Audit Metadata