skills/ruvnet/ruflo/cost-federation/Gen Agent Trust Hub

cost-federation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local JavaScript file located at plugins/ruflo-cost-tracker/scripts/federation.mjs using the permitted Bash tool. This script is intended to aggregate metrics from the federation spend event bus.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a consumer for external data from the federation-spend namespace, which creates a potential vulnerability surface for indirect prompt injection.
  • Ingestion points: Data is ingested from events published to the federation-spend namespace, including fields such as peerId and taskId.
  • Boundary markers: The documentation does not describe the use of delimiters or instructions to the agent to disregard potential instructions embedded in the event data.
  • Capability inventory: The skill has access to the Bash tool and executes local scripts via the node runtime.
  • Sanitization: There is no mention of sanitization, filtering, or strict schema validation performed on the event data before it is aggregated and reported to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — cost-federation