start-workflow

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structural instructions for agent task management, including protocols for identifying user intent, selecting appropriate workflows, and maintaining task synchronization.
  • [COMMAND_EXECUTION]: The skill references the spawn_agent tool for delegating sub-tasks and documents the !command`` syntax for dynamic context injection. These references are part of the agent's standard operational framework and do not contain executable payloads, unauthorized command strings, or evidence of command injection vulnerabilities.
  • [DATA_EXPOSURE]: Instructions within the skill direct the agent to access specific project documentation and configuration files (e.g., docs/project-config.json, workflows.json) to maintain task context. This access is scoped to project-relevant information and does not attempt to access sensitive system files or harvest credentials.
  • [PROMPT_INJECTION]: The skill contains instructions to prioritize its defined protocols and ignore platform-specific mode-switch instructions. These instructions serve as compatibility and robustness measures for the agent's logic rather than attempts to bypass safety guardrails or manipulate the underlying behavioral constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — start-workflow