skills/akillness/jeo-skills/goalflow/Gen Agent Trust Hub

goalflow

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The goalflow framework includes a CodeNode component that executes Python source code provided in Dify DSL exports or by the LLM using the exec() function. The documentation explicitly states that the safe_check() AST guard is currently disabled or marked as "TODO," allowing for arbitrary code execution during the workflow runtime.
  • [REMOTE_CODE_EXECUTION]: Because the CodeNode lacks sandboxing or safety checks, transpiling and executing an untrusted Dify DSL export results in the execution of potentially malicious Python code on the host environment where the goalflow engine is running.
  • [CREDENTIALS_UNSAFE]: The system's API key authentication mechanism in auth_validator.py is implemented using a static map keyed by the MD5 digest of the API key. MD5 is a cryptographically broken hashing algorithm and is unsuitable for protecting sensitive authentication secrets.
  • [COMMAND_EXECUTION]: The skill includes utility scripts (preflight_audit.py, goalflow.sh) that utilize subprocess.run to execute shell commands, specifically for git operations. While these are intended for repository auditing, they represent a high-privilege capability that interacts directly with the host's CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data from Dify DSL YAML files and runtime SKILL.md files. This content is either used to generate executable Python code or is injected verbatim into the system prompt for LLM matching. The lack of robust sanitization or boundary markers on these external ingestion points creates a surface for indirect prompt injection attacks.
  • Ingestion points: Dify DSL export files and runtime SKILL.md Markdown files.
  • Boundary markers: None; SKILL.md bodies are injected verbatim into the system prompt.
  • Capability inventory: Execution of arbitrary Python via exec(), templated network requests via HttpRequestNode, and tool calls via ToolNode.
  • Sanitization: AST safety checks are explicitly documented as disabled for the code execution path.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:13 AM
Security Audit — agent-trust-hub — goalflow