nutmeg-compute

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external sources such as football stat APIs, web pages, and downloaded files, which creates an inherent attack surface for indirect prompt injection.
  • Ingestion points: The skill instructions in SKILL.md explicitly reference processing content from external API responses, web scraping (e.g., Understat), and documentation retrieved via the mcp__football-docs__search_docs tool.
  • Boundary markers: The skill includes a 'Security' section that provides explicit instructions to the agent to treat all external content as untrusted and to avoid using it to modify system prompts or tool configurations.
  • Capability inventory: The skill utilizes tools with broad capabilities, including Bash, Write, and Read.
  • Sanitization: The instructions include a requirement for the agent to validate data shapes and schemas before processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:24 PM
Security Audit — agent-trust-hub — nutmeg-compute