intercom-automation
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to configure an external MCP server endpoint at
https://rube.app/mcp. This connection is required to access the Intercom toolset provided by the service. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted content from Intercom conversations and contact data. The documentation includes a safety recommendation to sanitize HTML input to prevent rendering issues.
- Ingestion points: External conversation bodies and contact metadata retrieved via Intercom tools.
- Boundary markers: None explicitly specified within the skill instructions.
- Capability inventory: The skill possesses extensive write capabilities, including creating and replying to conversations, assigning admins, and modifying contact associations.
- Sanitization: The 'Known Pitfalls' section advises the agent to sanitize HTML input to mitigate rendering risks within the Intercom platform.
Audit Metadata