ws-workflow-engine-bridge

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides a bridge to import and run multi-step prompt chains from JSON files, which introduces a surface for indirect prompt injection where instructions in the data could influence agent behavior. Ingestion points: Untrusted data enters the agent context via the 'import workflow from [path]' command in SKILL.md. Boundary markers: There are no specified delimiters or 'ignore' instructions provided to separate imported content from system guidelines. Capability inventory: The skill is granted 'file:read' and 'file:write' permissions to manage workspace outputs. Sanitization: No sanitization, escaping, or validation of the imported prompts is described.
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructions, with no accompanying executable code or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:42 AM
Security Audit — agent-trust-hub — ws-workflow-engine-bridge