skills/brida-ai/reflex/brida-reflex/Gen Agent Trust Hub

brida-reflex

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches product availability and discovery metadata from official vendor endpoints at https://brida.ai/reflex/llms.txt, https://brida.ai/reflex/agent.md, and https://brida.ai/reflex/agent.json.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text and documents, creating a surface for indirect prompt injection that is mitigated by strict structural guidelines. Ingestion points: User-provided text, support tickets, code diffs, and documents processed in references/use-case-index.md. Boundary markers: Instructions mandate using deterministic code first for validation and treating AI results as recommendation-only evidence. Capability inventory: No direct shell execution, dangerous subprocess calls, or file-write operations are defined within the skill's instruction set. Sanitization: Recommends using synthetic or correctly redacted fixtures and requires revalidation of current state before any side effects.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:00 PM
Security Audit — agent-trust-hub — brida-reflex