rivet-actors
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents an orchestration framework where agents (actors) ingest and process data from external queues, connections, and HTTP requests.
- Ingestion points: Multiple examples, such as
examples/docs/actors-queues/multiple-queues/index.ts, demonstrate actors retrieving and processing data payloads from internal message queues. - Boundary markers: As the skill provides a development kit for third-party implementation, the examples focus on logic rather than specific prompt delimiters, which is standard for architectural documentation.
- Capability inventory: Actors in the examples are granted capabilities for network operations (via
fetch), persistent storage access (viac.kv), and event broadcasting to connected clients. - Sanitization: The skill promotes secure development by providing dedicated examples for input validation, such as using the
zodlibrary to define and enforce strict schemas for incoming data inexamples/docs/actors-input/input-validation.ts.- [SAFE]: All external URLs and package references are associated with the verified vendor (rivet.dev) or well-known, trusted open-source libraries. The code is transparent and follows established patterns for agent orchestration frameworks.
Audit Metadata