workflow-skill-designer
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerability surface for indirect prompt injection because its primary function is to ingest external content (such as existing command files, requirements documents, or user-supplied text) and transform it into executable agent instructions.
- Ingestion points:
phases/01-requirements-analysis.mdreads content from user-specified file paths and interactive input. - Capability inventory: The skill uses
WriteandEdittools to generate new skills in the.claude/skills/directory. - Sanitization: The skill includes a
sanitizePhaseContentfunction designed to remove command-specific flags and invocation syntax. While it aims for high 'content fidelity' when preserving source prompts, the transformation logic is transparent and scoped to the user's local development environment. - [COMMAND_EXECUTION]: The skill uses the
Bashtool for benign administrative tasks related to the file structure of the generated skill package. - Evidence:
phases/02-orchestrator-design.mduses shell commands to create the necessary directory structure (e.g.,mkdir -p "${skillDir}/phases"). - [SAFE]: No malicious patterns such as credential exfiltration, data exposure, persistence mechanisms, or obfuscation were detected. The skill's operations are consistent with its stated purpose as a meta-development tool for organizing AI agent capabilities.
Audit Metadata