brida-reflex-conversation-turn-state
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured instructions for a semantic classification task (determining if a user has finished speaking). No security risks were identified.
- [DATA_EXPOSURE_EXFILTRATION]: The skill explicitly instructs the agent to avoid placing credentials in state or client bundles and warns against sending sensitive data to the 'non_sensitive' developer preview routes. These are positive security practices.
- [REMOTE_CODE_EXECUTION]: No remote code execution or dangerous shell commands were detected. The skill suggests using established integration methods like MCP, SDKs, or REST APIs.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied transcripts, it is framed as a classification task with defined output branches ('incomplete', 'complete_request', 'barge_in', 'ambiguous'), which naturally limits the impact of malicious content in the transcripts.
Audit Metadata