service-itsm-agentic-setup-cmdb-configure
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses and possesses the capability to modify organization settings via POST requests, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill ingests response bodies from the headless-360 dispatch tools when checking tenant provisioning status and feature enablement status.
- Boundary markers: While the ingested data is structured as JSON, the instructions do not specify explicit prompt delimiters to isolate this external content from the instruction context.
- Capability inventory: The skill is capable of triggering ITOM tenant provisioning and enabling the CMDB integration feature using write operations.
- Sanitization: The skill proactively mitigates risks by instructing the agent to explicitly unescape HTML entities and strip markup from external failure reason fields before displaying them to the user.
Audit Metadata