skills/ruvnet/ruflo/pii-detect/Gen Agent Trust Hub

pii-detect

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted data for PII analysis, creating a vulnerability where malicious instructions embedded in the analyzed text could influence the agent's behavior.\n- Ingestion points: External text enters the agent context via the <input-text> argument defined in SKILL.md.\n- Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions to isolate the untrusted input from the agent's primary instructions.\n- Capability inventory: The skill is configured with access to the Bash tool and several specialized PII detection tools (e.g., mcp__claude-flow__aidefence_*).\n- Sanitization: Absent. There is no evidence of input validation, filtering, or escaping before the data is processed by the detection tools.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 06:37 PM
Security Audit — agent-trust-hub — pii-detect