skills/ruvnet/ruflo/sparc-refine/Gen Agent Trust Hub

sparc-refine

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes artifacts and state information retrieved from a memory plugin which may contain data generated by users or other skills.
  • Ingestion points: The skill retrieves prior artifacts (specs, pseudocode, architecture) via mcp__plugin_ruflo-core_ruflo__memory_search in Phase 4, Step 1.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing retrieved memory.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, Edit, and mcp__plugin_ruflo-core_ruflo__neural_train which could be misused if malicious instructions are embedded in the retrieved code or specs.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the retrieved memory before execution (e.g., during test execution in Step 4 or regression in Step 9).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — sparc-refine