auth-md
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is configured to fetch protocol updates and specifications from external domains, including auth-md.com and official GitHub repositories associated with the WorkOS project. These downloads are used to ensure the agent has the most current version of the protocol documentation.
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell-based commands using
curlto interact with the isitagentready.com API for scanning domain readiness. - [INDIRECT_PROMPT_INJECTION]: The skill exposes an attack surface for indirect prompt injection via its validation workflow.
- Ingestion points: The skill accepts untrusted data by loading auth.md files from both local file system paths and remote URLs provided at runtime (Workflow: Validate in SKILL.md).
- Boundary markers: The instructions do not explicitly mandate the use of delimiters or specific system instructions to ignore embedded commands within the ingested markdown files.
- Capability inventory: The skill environment includes the ability to perform network requests and read local files to support validation logic.
- Sanitization: The skill employs a comprehensive set of validation rules (Basic and Full levels) defined in
references/validation-rules.mdto check the structure, fields, and consistency of the provided data.
Audit Metadata