brida-reflex-catalog-listing-signals

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch updated implementation guidance and API availability information from the vendor's official resources, including /reflex/llms.txt, /reflex/agent.md, and /reflex/agent.json.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and classify external catalog data (titles and descriptions). The risk of data-driven prompt injection is mitigated by the skill's explicit authority boundary, which restricts findings to recommendations and prohibits them from granting permissions for protected actions.
  • [SAFE]: The instructions include security best practices, such as requiring revalidation of authorization before any side effects and explicitly forbidding the storage of reusable credentials in the classification state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:21 PM
Security Audit — agent-trust-hub — brida-reflex-catalog-listing-signals