workflow-forge

Warn

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates dynamic script generation by instructing the agent to convert deterministic procedure steps into executable scripts stored on the filesystem.
  • [COMMAND_EXECUTION]: The skill performs direct, automated edits to SKILL.md files and project scripts to implement findings from sub-agent critiques.
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified where untrusted task data is ingested and processed by sub-agents. * Ingestion points: concrete task inputs passed to the Agent tool in the 'Run and critique' step. * Boundary markers: None identified; tasks are interpolated directly into agent prompts. * Capability inventory: Filesystem writes, script creation, and agent spawning (SKILL.md). * Sanitization: No sanitization or validation of the ingested task content is performed before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 11, 2026, 11:26 PM
Security Audit — agent-trust-hub — workflow-forge