trigger-cost-savings

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches optimization guidelines from the official Trigger.dev documentation domain (trigger.dev). This is a standard reference fetch for providing up-to-date service information.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web documentation and MCP tool outputs (run details and status). While this introduces a surface for processing potentially untrusted data, the risk is negligible as the skill's capabilities are limited to analytical reporting.
  • Ingestion points: Data enters the context via WebFetch from trigger.dev and outputs from Trigger.dev MCP tools (list_runs, get_run_details, get_current_worker) in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the ingested data.
  • Capability inventory: The skill's capabilities are restricted to reading data and generating a recommendation report. It does not have the ability to execute arbitrary commands, write to the file system, or perform unauthorized network operations.
  • Sanitization: There are no explicit sanitization or filtering steps defined for the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — trigger-cost-savings