npm-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill requires connection to a remote MCP endpoint at https://rube.app/mcp. This server is not on the trusted providers list and serves as the primary source for tool discovery and session management.
  • [PROMPT_INJECTION] (LOW): The skill is susceptible to indirect prompt injection (Category 8). 1. Ingestion points: The agent is instructed to fetch 'recommended execution plans' and 'known pitfalls' from the RUBE_SEARCH_TOOLS tool. 2. Boundary markers: No markers or 'ignore embedded instructions' warnings are present to isolate the fetched plans from the agent's core safety instructions. 3. Capability inventory: The skill has the ability to execute NPM tools and workbench commands via RUBE_MULTI_EXECUTE_TOOL. 4. Sanitization: No evidence of validation or sanitization of the remote plans is provided before the agent executes the suggested tool calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:40 PM