cost-booster-route
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted task descriptions which are analyzed and processed by downstream tools, creating a potential indirect prompt injection surface.
- Ingestion Points: Ingests external input via the
<task-description>argument or historically logged tasks retrieved usingmemory_searchinSKILL.md. - Boundary Markers: Absent. No delimiters or instructions are used to segregate the untrusted task data from the routing prompts.
- Capability Inventory: The skill is configured to use
mcp__plugin_ruflo-core_ruflo__hooks_route,mcp__plugin_ruflo-core_ruflo__memory_search,mcp__plugin_ruflo-core_ruflo__memory_list, andBashtools. - Sanitization: Absent. No validation or escaping is applied to the task descriptions before passing them to the routing mechanism.
Audit Metadata