cali-windmill-orchestration

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides detailed instructions for using the wmill CLI and curl to manage access tokens, test scripts, and interact with the Windmill API. These are standard developer tools for managing self-hosted or cloud-based Windmill environments.
  • [EXTERNAL_DOWNLOADS]: References official documentation from Windmill, technical specifications on GitHub, and well-known LLM provider API endpoints. These references target established and trusted services in the developer ecosystem.
  • [REMOTE_CODE_EXECUTION]: Describes the use of taskScript and workflow patterns to execute and orchestrate child scripts. This is the primary functionality of the Windmill platform and is used here for tool calling and complex automation logic.
  • [PROMPT_INJECTION]: The skill provides patterns for AI agents that consume untrusted user input to trigger automated actions, representing an indirect prompt injection surface.
  • Ingestion points: Untrusted user input enters the system through the text field in the orchestrator script or the user_message field in flow configurations.
  • Boundary markers: Not explicitly present in the provided templates, though the documentation references prompt engineering and system prompt management.
  • Capability inventory: Orchestrators are capable of executing various tools and child jobs via the taskScript function based on logic or LLM interpretations.
  • Sanitization: Proposes specific logic for filtering or stripping reasoning blocks and thinking tags from LLM responses to ensure clean conversation history.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 10:48 AM
Security Audit — agent-trust-hub — cali-windmill-orchestration