textcortex-automation
Warn
Audited by Gen Agent Trust Hub on Feb 18, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (MEDIUM): Dependency on an external MCP server endpoint (https://rube.app/mcp). This source is not on the list of trusted providers, posing a risk of unverifiable logic or updates.
- COMMAND_EXECUTION (LOW): Uses tools designed for remote operations (RUBE_MULTI_EXECUTE_TOOL, RUBE_REMOTE_WORKBENCH) which can perform actions on external platforms.
- PROMPT_INJECTION (LOW): Vulnerable to indirect prompt injection. 1. Ingestion points: Tool schemas and execution plans are ingested via RUBE_SEARCH_TOOLS. 2. Boundary markers: None identified to separate remote instructions from system prompts. 3. Capability inventory: Significant capabilities including RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH for executing tasks. 4. Sanitization: No evidence of input validation or schema sanitization for the data returned by the search tool.
Audit Metadata