decompose-workflow-skill

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [SAFE]: The skill provides a structured framework for refactoring agent skills. It includes several safety and validation steps, such as callstack simulation, exhaustive candidate mapping, and mandatory approval gates before any file writes are performed. All referenced tools appear to be internal workflow utilities compatible with the agent environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external source code as primary input.
  • Ingestion points: Target skill source code and repository context (Step 1).
  • Boundary markers: Absent; target code is read without explicit delimiters or instructions to ignore embedded commands.
  • Capability inventory: File system modification, new skill creation (via workflow-to-skill), and subagent orchestration.
  • Sanitization: Absent; the procedure does not define filtering or validation for the ingested code before it influences the generated output.
  • [NO_CODE]: The skill consists of Markdown instructions and procedural definitions. It does not contain embedded scripts, binaries, or hardcoded credentials. Tasks involving file manipulation or code analysis are delegated to external platform skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:07 PM
Security Audit — agent-trust-hub — decompose-workflow-skill