workflow
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a reference for chaining various internal plugins. All instructions and templates are benign and intended to guide the user through legitimate workflows.
- [EXTERNAL_DOWNLOADS]: The skill mentions installing plugins from the 'cogni-work/insight-wave' marketplace. As this matches the vendor's resource patterns, it is a standard operational procedure and does not represent a security risk.
- [COMMAND_EXECUTION]: The workflow guides describe the use of several internal commands (e.g.,
/marketing-setup,/trend-scout,/cogni-consult:consult-setup). These commands belong to the vendor's suite of tools and are used according to their documented purposes. - [DATA_EXPOSURE]: The skill reads the
.workspace-config.jsonfile to determine the user's language preference. This is a local configuration check for UI personalization and does not involve sensitive data exposure. - [INDIRECT_PROMPT_INJECTION]: The 'install-to-infographic' workflow mentions extracting themes from live websites using the 'claude-in-chrome' tool. While reading external content presents a potential ingestion surface for indirect prompt injection, the risk is minimal as the skill's own capabilities are restricted to 'Read' and 'Glob', and it does not perform dangerous operations with the ingested data.
Audit Metadata