webvizio-automation
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS] (LOW): The skill requires connecting to an external, non-whitelisted MCP server at
https://rube.app/mcpto function. - [INDIRECT_PROMPT_INJECTION] (LOW): The skill is designed to fetch and follow "recommended execution plans" and tool schemas dynamically from a remote API (
RUBE_SEARCH_TOOLS). - Ingestion points: JSON responses from the Rube MCP search tools endpoint.
- Boundary markers: No specific boundary markers or instructions to ignore embedded commands within the fetched data are present.
- Capability inventory: The agent can execute multiple tools and remote workbench operations (
RUBE_MULTI_EXECUTE_TOOL,RUBE_REMOTE_WORKBENCH) based on the fetched instructions. - Sanitization: There is no evidence of schema validation or sanitization of the remote execution plans before the agent processes them.
Audit Metadata