fw-ai-actions-app

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate development tool for the Freshworks platform and does not exhibit malicious behavior or security violations.- [CREDENTIALS_UNSAFE]: The documentation explicitly enforces the use of secure installation parameters (iparams) with 'secure: true' and OAuth for credential management, strictly forbidding the hardcoding of secrets.- [DATA_EXFILTRATION]: The skill includes a robust error-handling pattern ('__sanitizeMessageForClient') that redacts URLs and sensitive technical details from messages before they are returned to users, mitigating accidental data leakage risks.- [PROMPT_INJECTION]: The skill architecture uses structured JSON schemas and flat request parameters, which reduces the attack surface for injection. It also includes instructions for agents to maintain strict boundary markers when processing external data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 10:01 AM