flowra
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the user through installing a command-line interface by building it from a local project directory. This is intended for platform developers.- [DYNAMIC_EXECUTION]: Users can define custom JavaScript logic for tools and workflow nodes. These scripts are executed within the platform's hosted infrastructure, providing a mechanism for custom automation logic.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates building agents that process external user messages. To manage the risks of processing untrusted input, the instructions mandate the use of approval gates for actions such as sending emails or deleting data.- [SAFE]: The skill explicitly advises against common security pitfalls, such as hardcoding secrets or installing unrelated packages from public registries that could be mistaken for the official SDK.
Audit Metadata