freshservice

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI tool from the public NPM registry to function.
  • Evidence: npm install -g @membranehq/cli@latest in SKILL.md.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to manage authentication, establish connections to the Freshservice API, and execute actions.
  • Evidence: Commands such as membrane login, membrane connection ensure, and membrane action run are used throughout SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from Freshservice, such as ticket details and notes, which are considered untrusted ingestion points.
  • Ingestion points: list-tickets, get-ticket, and membrane request calls in SKILL.md.
  • Boundary markers: No specific delimiters are used to wrap the data retrieved from the API.
  • Capability inventory: The skill has the ability to execute shell commands via the membrane CLI and perform authenticated network operations to Freshservice.
  • Sanitization: There is no explicit mention of sanitizing or filtering the content retrieved from Freshservice before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 02:44 PM
Security Audit — agent-trust-hub — freshservice