review-team-deliverables

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from project task results and team memory, which presents a surface for indirect prompt injection where malicious instructions embedded in project artifacts could influence the agent's conclusions.
  • Ingestion points: Untrusted data enters the agent context through the mcp__plugin_ruflo-ai-team_ruflo-ai-team__task_list, mcp__plugin_ruflo-ai-team_ruflo-ai-team__memory_search, and mcp__plugin_ruflo-ai-team_ruflo-ai-team__team_get tools as defined in SKILL.md.
  • Boundary markers: The skill body lacks explicit boundary markers or directives (such as 'ignore embedded instructions') to isolate retrieved evidence from the system instructions.
  • Capability inventory: The skill is limited to reading data, searching memory, and generating reports/recommendations in SKILL.md; it does not possess dangerous write or shell execution capabilities.
  • Sanitization: There is no mention of sanitizing or validating the content of the retrieved task results before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — review-team-deliverables