docugenerate-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The skill requires connecting to an external MCP server endpoint (https://rube.app/mcp). This is a non-whitelisted dependency; however, the severity is reduced to LOW as it is central to the skill's primary purpose.
- REMOTE_CODE_EXECUTION (LOW): The skill utilizes RUBE_REMOTE_WORKBENCH for remote task execution via the Composio platform. Severity is reduced to LOW because this capability is required for the intended functionality.
- PROMPT_INJECTION (LOW): The skill exhibits an Indirect Prompt Injection surface (Category 8) by processing dynamic tool schemas from an external source. 1. Ingestion points: Tool definitions and schemas fetched via RUBE_SEARCH_TOOLS (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH (SKILL.md). 4. Sanitization: Absent.
Audit Metadata