neutrino-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [External Downloads] (LOW): The skill requires connection to a remote MCP server at https://rube.app/mcp which is not on the trusted repository or organization list.
  • [Indirect Prompt Injection] (LOW): The skill utilizes RUBE_SEARCH_TOOLS to dynamically ingest tool schemas and execution logic from the Rube server, creating an attack surface for instructions embedded in external tool definitions.
  • Ingestion points: Tool schemas and workflow plans returned from https://rube.app/mcp at runtime.
  • Boundary markers: Absent (the agent is instructed to follow 'recommended execution plans' from the server).
  • Capability inventory: Execution of discovered tools via RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH.
  • Sanitization: None (the skill does not instruct the agent to validate or escape the remote tool metadata).
  • [No Code] (SAFE): The skill consists only of documentation and instructions, containing no bundled scripts or binary executables.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:46 PM