skills/ruvnet/ruview/ruview-cli-api/Gen Agent Trust Hub

ruview-cli-api

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing vendor-specific CLI subcommands (wifi-densepose mat) and standard build processes using cargo and wasm-pack for vendor-owned crates.
  • [EXTERNAL_DOWNLOADS]: References official vendor Docker images (ruvnet/wifi-densepose) and utilizes standard Rust package management to fetch dependencies for vendor crates. These resources originate from the skill's own author and are consistent with standard development practices.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Survivor detection data and triage status (mat survivors), scan status summaries (mat status), and external sensing API responses.
  • Boundary markers: The skill includes an explicit instruction to "Keep input validation at the boundary (project rule)" when embedding crates.
  • Capability inventory: The skill employs Bash for command execution and Read/Write/Edit for file manipulation.
  • Sanitization: Instructions mandate adherence to project-level input validation protocols at the application boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:03 AM
Security Audit — agent-trust-hub — ruview-cli-api