rivet-dynamic-apps
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill facilitates the deployment of application code represented as strings via the
@rivet-dev/dynamic-appslibrary. This dynamic execution is the central feature of the skill, intended to allow AI-generated backends to run in isolated environments. - [INDIRECT_PROMPT_INJECTION]: The architecture is designed to ingest and execute code generated by AI agents. This introduces an inherent surface where instructions from external data could influence the generated code. In the provided examples, this is managed through the platform's app deployment framework.
- Ingestion points: The
deployAppfunction inexamples/apps-hello-world/src/deploy.tsaccepts code strings for deployment. - Boundary markers: None identified in the example code snippets.
- Capability inventory: The framework is capable of routing HTTP requests to the deployed logic as seen in
examples/apps-hello-world/src/server.ts. - Sanitization: No explicit sanitization or validation of the code strings is shown in these illustrative examples.
Audit Metadata