cost-federation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local JavaScript file located at
plugins/ruflo-cost-tracker/scripts/federation.mjsusing the permittedBashtool. This script is intended to aggregate metrics from the federation spend event bus. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a consumer for external data from the
federation-spendnamespace, which creates a potential vulnerability surface for indirect prompt injection. - Ingestion points: Data is ingested from events published to the
federation-spendnamespace, including fields such aspeerIdandtaskId. - Boundary markers: The documentation does not describe the use of delimiters or instructions to the agent to disregard potential instructions embedded in the event data.
- Capability inventory: The skill has access to the
Bashtool and executes local scripts via thenoderuntime. - Sanitization: There is no mention of sanitization, filtering, or strict schema validation performed on the event data before it is aggregated and reported to the user.
Audit Metadata