agentic-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • External Content Integration: The skill identifies and loads instruction files from a remote repository (github/gh-aw). While this facilitates dynamic updates to workflow logic, it creates a dependency on external resources to define agent behavior.
  • Indirect Prompt Injection Surface: The agent is instructed to load and 'follow directly' the content of remote markdown files. This behavior represents an ingestion surface for external instructions. If the remote source were to contain unexpected commands or directives, the agent might process them as part of its core logic, as there are no explicit boundary markers or validation steps defined for the ingested text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:31 AM
Security Audit — agent-trust-hub — agentic-workflows