trigger-realtime
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to monitor and display task execution data, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through task run status updates, metadata, outputs (
run.output), and real-time AI streams (parts.join("")) as shown inSKILL.mdandreferences/realtime.md. - Boundary markers: The provided code examples do not include explicit boundary markers or warnings to the AI agent to ignore instructions embedded within the streamed data.
- Capability inventory: The skill itself uses the
@trigger.dev/sdkand@trigger.dev/react-hooksfor network communication and UI rendering; it does not contain direct file-write or shell execution capabilities within its own code. - Sanitization: The examples show direct interpolation of task output and streams into the UI/console (e.g.,
{JSON.stringify(run.output)},console.log(run.output)) without visible sanitization or validation steps.
Audit Metadata