skills/runtypelabs/skills/runtype/Gen Agent Trust Hub

runtype

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides informational documentation and routing logic for the Runtype platform and does not contain any malicious instructions or security vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill references official vendor infrastructure at api.runtype.com and utilizes well-known services like jsdelivr.net for platform operations and asset delivery.
  • [REMOTE_CODE_EXECUTION]: Documentation describes platform features for executing scripts in sandboxed environments (QuickJS, Cloudflare Workers) and browser-side tool execution (WebMCP) as part of standard product functionality.
  • [DATA_EXFILTRATION]: The platform documentation identifies potential surfaces for indirect prompt injection. 1. Ingestion points: Web crawling, URL fetching, and webhook payloads (references/flow-steps.md, references/surfaces.md). 2. Boundary markers: No specific delimiters or instruction warnings are mandated in the documentation for untrusted data. 3. Capability inventory: Support for automated email, SMS, tool execution, and sandbox deployment (references/mcp-tools.md, references/flow-steps.md). 4. Sanitization: The documentation does not specify mandatory sanitization or escaping of external content before prompt interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:42 AM
Security Audit — agent-trust-hub — runtype