sitespeakai-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill's architecture relies on dynamic tool discovery, which presents a surface for indirect prompt injection if the remote server were compromised.\n
  • Ingestion points: Tool definitions and schemas returned by RUBE_SEARCH_TOOLS as described in SKILL.md.\n
  • Boundary markers: Absent; the skill does not instruct the agent to ignore instructions embedded within the tool schemas.\n
  • Capability inventory: The skill utilizes RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH which can execute arbitrary code/tools via the Composio toolkit.\n
  • Sanitization: Absent; the instructions prioritize schema compliance over input validation.\n- [External Downloads] (SAFE): The skill references https://rube.app/mcp for MCP server configuration. This is the legitimate endpoint for the Rube/Composio service and is required for functionality.\n- [Dynamic Execution] (LOW): The workflow utilizes RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH to execute tools discovered at runtime, which is a standard pattern for MCP-based skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:44 PM