textcortex-automation

Warn

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • EXTERNAL_DOWNLOADS (MEDIUM): Dependency on an external MCP server endpoint (https://rube.app/mcp). This source is not on the list of trusted providers, posing a risk of unverifiable logic or updates.
  • COMMAND_EXECUTION (LOW): Uses tools designed for remote operations (RUBE_MULTI_EXECUTE_TOOL, RUBE_REMOTE_WORKBENCH) which can perform actions on external platforms.
  • PROMPT_INJECTION (LOW): Vulnerable to indirect prompt injection. 1. Ingestion points: Tool schemas and execution plans are ingested via RUBE_SEARCH_TOOLS. 2. Boundary markers: None identified to separate remote instructions from system prompts. 3. Capability inventory: Significant capabilities including RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH for executing tasks. 4. Sanitization: No evidence of input validation or schema sanitization for the data returned by the search tool.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 01:44 AM