sparc-refine
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes artifacts and state information retrieved from a memory plugin which may contain data generated by users or other skills.
- Ingestion points: The skill retrieves prior artifacts (specs, pseudocode, architecture) via
mcp__plugin_ruflo-core_ruflo__memory_searchin Phase 4, Step 1. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing retrieved memory.
- Capability inventory: The skill has access to powerful tools including
Bash,Write,Edit, andmcp__plugin_ruflo-core_ruflo__neural_trainwhich could be misused if malicious instructions are embedded in the retrieved code or specs. - Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the retrieved memory before execution (e.g., during test execution in Step 4 or regression in Step 9).
Audit Metadata