zenserp-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [No Code] (SAFE): The skill consists of text-based instructions and metadata only. There are no scripts or binary files, eliminating the risk of local code execution.\n- [Indirect Prompt Injection] (LOW): The skill possesses an indirect prompt injection surface. Evidence: (1) Ingestion points: Data enters the context via RUBE_SEARCH_TOOLS output. (2) Boundary markers: No delimiters or 'ignore embedded instructions' warnings are present in the provided templates. (3) Capability inventory: The skill can trigger subprocesses via RUBE_MULTI_EXECUTE_TOOL and RUBE_REMOTE_WORKBENCH. (4) Sanitization: No sanitization, escaping, or validation of the fetched tool schemas is defined.\n- [External Dependency] (SAFE): The skill references an external MCP server (rube.app/mcp). While this is an untrusted third-party source, referencing it is the fundamental purpose of the skill and does not involve the direct download of executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:41 PM