freshdesk-automation

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes ticket descriptions and replies from external users, which are considered untrusted ingestion points. Ingestion points: Ticket content retrieved via tools like FRESHDESK_VIEW_TICKET and FRESHDESK_LIST_ALL_TICKET_CONVERSATIONS as described in SKILL.md. Boundary markers: None; the instructions do not implement delimiters or ignore-instructions to separate untrusted data from system instructions. Capability inventory: The agent has tools to send replies (FRESHDESK_REPLY_TO_TICKET), update ticket states (FRESHDESK_UPDATE_TICKET), and modify contact details. Sanitization: No sanitization or validation of the HTML-formatted ticket body is specified in the workflows.
  • [EXTERNAL_DOWNLOADS]: The skill requires the configuration of a remote MCP server endpoint at https://rube.app/mcp to access the Freshdesk toolkit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — freshdesk-automation