workflow-mastery

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends automating workflows by configuring PostToolUse hooks in the environment settings to execute dotnet format automatically and pre-authorizing standard dotnet CLI commands (such as build, test, run, and ef) to streamline the development process and reduce manual approval prompts.
  • [PROMPT_INJECTION]: The patterns described for the 'Verification Loop' and specialized 'Subagents' involve the agent processing project source code, build logs, and test outputs. This configuration represents an inherent surface for indirect prompt injection, where adversarial instructions embedded in data could attempt to influence agent behavior.
  • Ingestion points: Project source code, build diagnostics, and test results referenced in the verification pipeline (SKILL.md).
  • Boundary markers: None identified; the skill does not suggest specific delimiters or instructions to ignore embedded directions in processed data.
  • Capability inventory: Shell command execution via the dotnet CLI (SKILL.md).
  • Sanitization: None identified; the skill focuses on workflow efficiency rather than data sanitization or input validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 05:20 AM
Security Audit — agent-trust-hub — workflow-mastery