runtype
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides informational documentation and routing logic for the Runtype platform and does not contain any malicious instructions or security vulnerabilities.
- [EXTERNAL_DOWNLOADS]: The skill references official vendor infrastructure at api.runtype.com and utilizes well-known services like jsdelivr.net for platform operations and asset delivery.
- [REMOTE_CODE_EXECUTION]: Documentation describes platform features for executing scripts in sandboxed environments (QuickJS, Cloudflare Workers) and browser-side tool execution (WebMCP) as part of standard product functionality.
- [DATA_EXFILTRATION]: The platform documentation identifies potential surfaces for indirect prompt injection. 1. Ingestion points: Web crawling, URL fetching, and webhook payloads (references/flow-steps.md, references/surfaces.md). 2. Boundary markers: No specific delimiters or instruction warnings are mandated in the documentation for untrusted data. 3. Capability inventory: Support for automated email, SMS, tool execution, and sandbox deployment (references/mcp-tools.md, references/flow-steps.md). 4. Sanitization: The documentation does not specify mandatory sanitization or escaping of external content before prompt interpolation.
Audit Metadata