control-d-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill possesses an indirect prompt injection surface as it dynamically retrieves tool definitions and execution plans from the Rube MCP server and instructs the agent to follow them. \n
  • Ingestion points: Tool discovery results from RUBE_SEARCH_TOOLS (SKILL.md). \n
  • Boundary markers: Absent; the instructions do not provide delimiters or warnings to ignore instructions embedded in the tool schemas. \n
  • Capability inventory: The skill uses RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH to perform Control D operations. \n
  • Sanitization: Absent; the agent is instructed to use the exact field names and types returned by the search result. \n- [Safe Behavior] (SAFE): No malicious patterns, obfuscation, or hardcoded secrets were detected. The skill is instructional and its external dependency is transparently disclosed.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:43 PM