stinkyboy

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the execution of thousands of external tools whose outputs are ingested by the agent. \n- Ingestion points: Data returned from call_tool and create_and_call. \n- Boundary markers: None; the skill does not provide instructions to help the agent distinguish between tool output and its own system instructions. \n- Capability inventory: The agent can search, detail, and execute arbitrary tools on a remote catalog. \n- Sanitization: None; tool outputs are not validated or filtered before processing. \n- [DYNAMIC_EXECUTION]: The create_and_call tool and the synthesize option in catalog_search allow for runtime compilation and execution of logic based on natural language descriptions on a remote server. \n- [REMOTE_CODE_EXECUTION]: The skill connects to a remote service (https://mcp.stinkyboy.co/mcp) to run tool logic, delegating execution tasks to an external infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 12:26 AM
Security Audit — agent-trust-hub — stinkyboy