neutrino-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [External Downloads] (LOW): The skill requires connection to a remote MCP server at
https://rube.app/mcpwhich is not on the trusted repository or organization list. - [Indirect Prompt Injection] (LOW): The skill utilizes
RUBE_SEARCH_TOOLSto dynamically ingest tool schemas and execution logic from the Rube server, creating an attack surface for instructions embedded in external tool definitions. - Ingestion points: Tool schemas and workflow plans returned from
https://rube.app/mcpat runtime. - Boundary markers: Absent (the agent is instructed to follow 'recommended execution plans' from the server).
- Capability inventory: Execution of discovered tools via
RUBE_MULTI_EXECUTE_TOOLandRUBE_REMOTE_WORKBENCH. - Sanitization: None (the skill does not instruct the agent to validate or escape the remote tool metadata).
- [No Code] (SAFE): The skill consists only of documentation and instructions, containing no bundled scripts or binary executables.
Audit Metadata