brida-reflex-conversation-turn-state

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for a semantic classification task (determining if a user has finished speaking). No security risks were identified.
  • [DATA_EXPOSURE_EXFILTRATION]: The skill explicitly instructs the agent to avoid placing credentials in state or client bundles and warns against sending sensitive data to the 'non_sensitive' developer preview routes. These are positive security practices.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or dangerous shell commands were detected. The skill suggests using established integration methods like MCP, SDKs, or REST APIs.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied transcripts, it is framed as a classification task with defined output branches ('incomplete', 'complete_request', 'barge_in', 'ambiguous'), which naturally limits the impact of malicious content in the transcripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:21 PM
Security Audit — agent-trust-hub — brida-reflex-conversation-turn-state