brida-reflex-document-invoice-review

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured instructions and synthetic data for implementing a document review workflow without requesting sensitive permissions or credentials.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch documentation and discovery metadata (e.g., /reflex/llms.txt, /reflex/agent.json) from the official Brida vendor infrastructure to determine API availability.
  • [CREDENTIALS_UNSAFE]: The instructions explicitly forbid the inclusion of reusable credentials in the system state, promoting secure secret management practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing invoice summaries but mitigates risks through clear boundaries. Ingestion points: references/custom-reflex.json, references/playbook.md, and live /reflex/ endpoints. Boundary markers: Explicit synthetic invoice summary labeling and non_sensitive data classification. Capability inventory: Environment inspection and tool-based integration via MCP, SDK, or REST. Sanitization: Mandatory deterministic validation and arithmetic are required in host code before semantic analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:21 PM
Security Audit — agent-trust-hub — brida-reflex-document-invoice-review