trigger-cost-savings
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches optimization guidelines from the official Trigger.dev documentation domain (trigger.dev). This is a standard reference fetch for providing up-to-date service information.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web documentation and MCP tool outputs (run details and status). While this introduces a surface for processing potentially untrusted data, the risk is negligible as the skill's capabilities are limited to analytical reporting.
- Ingestion points: Data enters the context via WebFetch from trigger.dev and outputs from Trigger.dev MCP tools (list_runs, get_run_details, get_current_worker) in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the ingested data.
- Capability inventory: The skill's capabilities are restricted to reading data and generating a recommendation report. It does not have the ability to execute arbitrary commands, write to the file system, or perform unauthorized network operations.
- Sanitization: There are no explicit sanitization or filtering steps defined for the ingested content.
Audit Metadata