brida-reflex-work-priority
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to consult external files for service availability and interface updates. Evidence: SKILL.md directing the agent to read /reflex/llms.txt, /reflex/agent.md, and /reflex/agent.json from the vendor's live environment.
- [INDIRECT_PROMPT_INJECTION]: The skill interprets natural language task descriptions to automate priority routing, which is a potential surface for injection attacks intended to manipulate the scheduling outcome. Ingestion points: SKILL.md (Step 1 of Execute Autonomously) and the 'task' and 'impact' fields in references/custom-reflex.json. Boundary markers: Absent; there are no instructions provided to distinguish between task data and potential embedded commands. Capability inventory: The skill uses MCP, SDKs, or REST APIs to route tasks to specific branches (run_now, defer, human_attention). Sanitization: Absent; the skill does not specify any validation or filtering for the ingested task state.
Audit Metadata