brida-reflex-semantic-rule-check

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches live status and configuration files (such as llms.txt, agent.md, and agent.json) from the vendor's hosted infrastructure to verify feature availability.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of artifact excerpts for semantic analysis.
  • Ingestion points: Artifact excerpts processed by the Reflex integration surface (referenced in SKILL.md and references/playbook.md).
  • Boundary markers: The workflow utilizes bounded excerpts and single-rule focus to limit context exposure.
  • Capability inventory: The skill is restricted to qualitative judgment and recommendation; the Authority section in SKILL.md explicitly denies permissions for merges, deploys, payments, or destructive mutations.
  • Sanitization: The instructions mandate that exact parsing and policy remain in deterministic host code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:22 PM
Security Audit — agent-trust-hub — brida-reflex-semantic-rule-check