control-d-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill possesses an indirect prompt injection surface as it dynamically retrieves tool definitions and execution plans from the Rube MCP server and instructs the agent to follow them. \n
- Ingestion points: Tool discovery results from
RUBE_SEARCH_TOOLS(SKILL.md). \n - Boundary markers: Absent; the instructions do not provide delimiters or warnings to ignore instructions embedded in the tool schemas. \n
- Capability inventory: The skill uses
RUBE_MULTI_EXECUTE_TOOLandRUBE_REMOTE_WORKBENCHto perform Control D operations. \n - Sanitization: Absent; the agent is instructed to use the exact field names and types returned by the search result. \n- [Safe Behavior] (SAFE): No malicious patterns, obfuscation, or hardcoded secrets were detected. The skill is instructional and its external dependency is transparently disclosed.
Audit Metadata