freshdesk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI from the public npm registry using npm install -g @membranehq/cli@latest. This is a standard procedure for using Membrane-based integrations and targets the official tool for this service.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external source (Freshdesk API) including tickets, contacts, and notes. This data is interpolated into the agent's context during operations like listing or retrieving tickets, creating an attack surface where malicious content within a ticket could attempt to influence the agent's behavior.
  • Ingestion points: Data enters the context via membrane action run list-tickets, get-ticket, list-contacts, etc., and raw proxy requests in SKILL.md.
  • Boundary markers: The skill does not explicitly define delimiters for external data or instructions to ignore embedded commands within the Freshdesk content.
  • Capability inventory: The skill has capabilities to execute shell commands via the Membrane CLI, make network requests to the Freshdesk API, and manage connections.
  • Sanitization: There is no evidence of specific sanitization or filtering of the content retrieved from Freshdesk before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:13 AM
Security Audit — agent-trust-hub — freshdesk