review-team-deliverables
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from project task results and team memory, which presents a surface for indirect prompt injection where malicious instructions embedded in project artifacts could influence the agent's conclusions.
- Ingestion points: Untrusted data enters the agent context through the
mcp__plugin_ruflo-ai-team_ruflo-ai-team__task_list,mcp__plugin_ruflo-ai-team_ruflo-ai-team__memory_search, andmcp__plugin_ruflo-ai-team_ruflo-ai-team__team_gettools as defined in SKILL.md. - Boundary markers: The skill body lacks explicit boundary markers or directives (such as 'ignore embedded instructions') to isolate retrieved evidence from the system instructions.
- Capability inventory: The skill is limited to reading data, searching memory, and generating reports/recommendations in SKILL.md; it does not possess dangerous write or shell execution capabilities.
- Sanitization: There is no mention of sanitizing or validating the content of the retrieved task results before the agent processes them.
Audit Metadata