dynamic-workflow-mode

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for generating "Dynamic Workflow Harnesses" that ingest external inputs including URLs and unspecified data sources. This creates a potential surface where malicious instructions embedded in external content could influence the agent's logic during harness creation or execution.
  • Ingestion points: The "Inputs" section of the harness template in SKILL.md identifies files, URLs, and data sources as primary entry points.
  • Boundary markers: The instructions lack specific guidance on using delimiters or explicit "ignore embedded instructions" prompts when handling these external inputs.
  • Capability inventory: The skill encourages the generation of scripts, the execution of eval commands, and the creation of status files across the workspace as part of the harness lifecycle.
  • Sanitization: No explicit sanitization, validation, or escaping mechanisms for external input are provided in the workflow logic.
  • [DYNAMIC_EXECUTION]: The core functionality involves the "Task-Local Harness Template," which generates and executes scripts and evaluation commands at runtime based on the task context. While the skill aims for disciplined automation, the generation and execution of code from runtime-defined templates is an inherent risk factor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — dynamic-workflow-mode