trigger-realtime

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to monitor and display task execution data, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: Data enters the agent's context through task run status updates, metadata, outputs (run.output), and real-time AI streams (parts.join("")) as shown in SKILL.md and references/realtime.md.
  • Boundary markers: The provided code examples do not include explicit boundary markers or warnings to the AI agent to ignore instructions embedded within the streamed data.
  • Capability inventory: The skill itself uses the @trigger.dev/sdk and @trigger.dev/react-hooks for network communication and UI rendering; it does not contain direct file-write or shell execution capabilities within its own code.
  • Sanitization: The examples show direct interpolation of task output and streams into the UI/console (e.g., {JSON.stringify(run.output)}, console.log(run.output)) without visible sanitization or validation steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — trigger-realtime