skills/felipeangeli/skills/workflow/Gen Agent Trust Hub

workflow

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions use authoritative language to command the agent to disregard its internal training data in favor of the provided text.
  • Evidence: "Your knowledge of workflow is outdated." and "Follow these instructions before starting on any workflow-related tasks:" in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow pattern that ingests untrusted user data into an AI agent context, creating a potential vulnerability to embedded malicious instructions.
  • Ingestion points: The myAgentWorkflow function in SKILL.md accepts a userMessage argument.
  • Boundary markers: Absent; the input is interpolated directly into the agent.stream messages array.
  • Capability inventory: The skill utilizes fetch for network requests and provides tools for data lookup and workflow orchestration.
  • Sanitization: Absent; there is no evidence of filtering or escaping the user-provided content.
  • [COMMAND_EXECUTION]: The skill documents the use of project-specific CLI tools for debugging and monitoring.
  • Evidence: Multiple npx workflow commands are listed for health checks, dashboard access, and run inspection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — workflow