scrapegraph-ai-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (LOW): This skill has an indirect prompt injection surface by design. Ingestion points: Data enters the agent's context through responses from the
RUBE_SEARCH_TOOLSandRUBE_MANAGE_CONNECTIONStools, which retrieve data from the externalrube.appMCP server. Boundary markers: The instructions do not provide boundary markers or explicit warnings to ignore potential instructions embedded in the tool discovery results. Capability inventory: The skill gives the agent the ability to execute any tool found during discovery using theRUBE_MULTI_EXECUTE_TOOLcapability. Sanitization: No validation or sanitization is performed on the tool schemas or arguments returned by the search tools. - [External Downloads] (LOW): The skill requires a connection to a third-party MCP server at
https://rube.app/mcp. As this is the primary purpose of the skill, the severity is downgraded per the [TRUST-SCOPE-RULE], though it remains an external dependency from a non-whitelisted source.
Audit Metadata