brida-reflex-code-change-classification

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from code repositories to categorize software changes. 1. Ingestion points: Commit messages, diff summaries, and project environment state as identified in SKILL.md and references/playbook.md. 2. Boundary markers: The instructions mandate the use of deterministic host code for parsing and require that only normalized, non-sensitive state be passed to the model. 3. Capability inventory: The skill is recommendation-only and explicitly lacks authorization for sensitive actions like deployments, merges, or credential management. 4. Sanitization: Inputs are normalized according to a fixed schema defined in references/custom-reflex.json and restricted to a non-sensitive data class.
  • [EXTERNAL_DOWNLOADS]: The skill references reading live metadata and configuration files from the vendor's infrastructure. Evidence: SKILL.md instructs the agent to check /reflex/llms.txt, /reflex/agent.md, and /reflex/agent.json for current service availability information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:22 PM
Security Audit — agent-trust-hub — brida-reflex-code-change-classification