cost-booster-route

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted task descriptions which are analyzed and processed by downstream tools, creating a potential indirect prompt injection surface.
  • Ingestion Points: Ingests external input via the <task-description> argument or historically logged tasks retrieved using memory_search in SKILL.md.
  • Boundary Markers: Absent. No delimiters or instructions are used to segregate the untrusted task data from the routing prompts.
  • Capability Inventory: The skill is configured to use mcp__plugin_ruflo-core_ruflo__hooks_route, mcp__plugin_ruflo-core_ruflo__memory_search, mcp__plugin_ruflo-core_ruflo__memory_list, and Bash tools.
  • Sanitization: Absent. No validation or escaping is applied to the task descriptions before passing them to the routing mechanism.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — cost-booster-route