service-itsm-agentic-setup-cmdb-configure

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses and possesses the capability to modify organization settings via POST requests, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill ingests response bodies from the headless-360 dispatch tools when checking tenant provisioning status and feature enablement status.
  • Boundary markers: While the ingested data is structured as JSON, the instructions do not specify explicit prompt delimiters to isolate this external content from the instruction context.
  • Capability inventory: The skill is capable of triggering ITOM tenant provisioning and enabling the CMDB integration feature using write operations.
  • Sanitization: The skill proactively mitigates risks by instructing the agent to explicitly unescape HTML entities and strip markup from external failure reason fields before displaying them to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:35 PM
Security Audit — agent-trust-hub — service-itsm-agentic-setup-cmdb-configure