skills/adobe/skills/workfront-actions/Gen Agent Trust Hub

workfront-actions

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly promotes secure handling of credentials by advising against hardcoding and recommending the use of environment-based inputs wired through params. It warns against logging tokens and reading from process.env at runtime.
  • [EXTERNAL_DOWNLOADS]: The boilerplate code and instructions demonstrate fetching data from Workfront and Adobe Planning APIs. These network operations are intended for the skill's primary purpose and utilize user-provided instance URLs and IMS tokens.
  • [COMMAND_EXECUTION]: The skill references the use of standard Adobe CLI tools (e.g., aio app add action, aio app deploy) for project management and deployment within the Adobe I/O Runtime environment.
  • [PROMPT_INJECTION]: The skill describes processing data from external APIs (Workfront) which represents an indirect prompt injection surface if the resulting data is subsequently fed into an LLM context without proper sanitization or boundary markers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 04:21 PM
Security Audit — agent-trust-hub — workfront-actions