workflow-orchestrator

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because its primary function is to facilitate the sequential passing of data from potentially untrusted sources to various downstream capabilities.
  • Ingestion points: Workflows can ingest untrusted data from skills like web-scraper, api-fetcher, file-importer, and hubspot-connector as described in SKILL.md and the skill catalog.
  • Boundary markers: The orchestration logic does not implement or describe the use of delimiters, escaping, or explicit instructions for the agent to ignore embedded commands within the handoff data.
  • Capability inventory: The orchestrator can trigger significant side effects by passing data to skills like email-automation, cloud-upload, database-modifier, and social-scheduler.
  • Sanitization: The documentation lacks mention of sanitizing or validating external content before it is processed by downstream skills in a chain.
  • [NO_CODE]: This skill contains no executable scripts or binaries. It consists entirely of documentation and instruction files that define a high-level workflow syntax for the agent to follow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 02:44 PM
Security Audit — agent-trust-hub — workflow-orchestrator