zoho-inventory-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill instructions require the user to configure a third-party MCP server endpoint (https://rube.app/mcp). This creates a dependency on an external service not included in the trusted organizational whitelist provided in the security skill instructions.
  • [PROMPT_INJECTION] (LOW): The skill is susceptible to indirect prompt injection (Category 8). Ingestion points: The agent retrieves tool definitions, slugs, and recommended execution plans dynamically via RUBE_SEARCH_TOOLS. Boundary markers: Absent; the instructions do not specify any delimiters or safety warnings to ignore potentially malicious instructions embedded within the fetched tool schemas. Capability inventory: The skill utilizes powerful tools such as RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH, which allow for significant action and remote tool execution based on the ingested data. Sanitization: Absent; there is no mention of validation or sanitization of the external tool metadata before the agent interprets and executes the tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:33 PM