brida-reflex-incoming-message-risk

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for analyzing external messages which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: The skill ingests data via the messageExcerpt and subject fields as defined in the custom-reflex.json fixtures and SKILL.md.
  • Boundary markers: The instructions in custom-reflex.json include specific boundary directives: "Judge only the message context supplied; do not infer facts or authority that are absent."
  • Capability inventory: The skill focus is recommendation classification; no high-privilege capabilities such as arbitrary command execution are defined.
  • Sanitization: The playbook.md guidance promotes using redacted or synthetic excerpts and supply only bounded context.
  • [EXTERNAL_DOWNLOADS]: The skill instructions in SKILL.md direct the agent to fetch configuration and availability data from live hosted files (/reflex/llms.txt, /reflex/agent.md, and /reflex/agent.json) associated with the vendor's infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:22 PM
Security Audit — agent-trust-hub — brida-reflex-incoming-message-risk