reflex-process-management

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is authored by the framework vendor (reflex-dev) and utilizes their proprietary reflex CLI tool as intended for application development.\n- [COMMAND_EXECUTION]: The instructions include shell commands (lsof, kill, ss, fuser, tee) to manage the application lifecycle. These commands are properly scoped to the specific network ports and log files associated with the application.\n- [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to extract a port number from reflex.log. While this file could contain untrusted data, the specific use case of identifying a port for process management is a standard operational requirement and is considered safe in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 02:50 AM