goalflow
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [DYNAMIC_EXECUTION]: The goalflow framework includes a
CodeNodecomponent that executes Python source code provided in Dify DSL exports or by the LLM using theexec()function. The documentation explicitly states that thesafe_check()AST guard is currently disabled or marked as "TODO," allowing for arbitrary code execution during the workflow runtime. - [REMOTE_CODE_EXECUTION]: Because the
CodeNodelacks sandboxing or safety checks, transpiling and executing an untrusted Dify DSL export results in the execution of potentially malicious Python code on the host environment where the goalflow engine is running. - [CREDENTIALS_UNSAFE]: The system's API key authentication mechanism in
auth_validator.pyis implemented using a static map keyed by the MD5 digest of the API key. MD5 is a cryptographically broken hashing algorithm and is unsuitable for protecting sensitive authentication secrets. - [COMMAND_EXECUTION]: The skill includes utility scripts (
preflight_audit.py,goalflow.sh) that utilizesubprocess.runto execute shell commands, specifically for git operations. While these are intended for repository auditing, they represent a high-privilege capability that interacts directly with the host's CLI. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data from Dify DSL YAML files and runtime
SKILL.mdfiles. This content is either used to generate executable Python code or is injected verbatim into the system prompt for LLM matching. The lack of robust sanitization or boundary markers on these external ingestion points creates a surface for indirect prompt injection attacks. - Ingestion points: Dify DSL export files and runtime
SKILL.mdMarkdown files. - Boundary markers: None;
SKILL.mdbodies are injected verbatim into the system prompt. - Capability inventory: Execution of arbitrary Python via
exec(), templated network requests viaHttpRequestNode, and tool calls viaToolNode. - Sanitization: AST safety checks are explicitly documented as disabled for the code execution path.
Audit Metadata