freshdesk-automation
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes ticket descriptions and replies from external users, which are considered untrusted ingestion points. Ingestion points: Ticket content retrieved via tools like FRESHDESK_VIEW_TICKET and FRESHDESK_LIST_ALL_TICKET_CONVERSATIONS as described in SKILL.md. Boundary markers: None; the instructions do not implement delimiters or ignore-instructions to separate untrusted data from system instructions. Capability inventory: The agent has tools to send replies (FRESHDESK_REPLY_TO_TICKET), update ticket states (FRESHDESK_UPDATE_TICKET), and modify contact details. Sanitization: No sanitization or validation of the HTML-formatted ticket body is specified in the workflows.
- [EXTERNAL_DOWNLOADS]: The skill requires the configuration of a remote MCP server endpoint at https://rube.app/mcp to access the Freshdesk toolkit.
Audit Metadata