claid-ai-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS] (LOW): The skill directs users to configure an external MCP server at
https://rube.app/mcp. While this is an external dependency, it is a standard configuration step for MCP-based skills. - [INDIRECT_PROMPT_INJECTION] (LOW): There is a potential attack surface where tool schemas or execution plans returned by the external
RUBE_SEARCH_TOOLScould contain malicious instructions. - Ingestion points: Data returned from
RUBE_SEARCH_TOOLS. - Boundary markers: Absent in the instructions.
- Capability inventory:
RUBE_MULTI_EXECUTE_TOOLprovides the ability to execute functional tools. - Sanitization: No sanitization logic is specified in the prompt instructions.
- [DATA_EXPOSURE] (SAFE): No hardcoded credentials, API keys, or sensitive file paths (e.g., .ssh, .aws) were detected in the skill content.
- [PROMPT_INJECTION] (SAFE): No instructions attempting to bypass safety filters, override system prompts, or extract system instructions were found.
Audit Metadata