agentic-workflows
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch prompt files and sub-skills from the
github/gh-awrepository. These resources are hosted on a well-known service and are owned by the official author, representing the primary intended functionality of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files to determine agent behavior, creating a surface for indirect prompt injection.
- Ingestion points: Files under
.github/aw/and.github/skills/within thegithub/gh-awrepository (SKILL.md). - Boundary markers: Absent; the skill follows the loaded content directly without explicit delimiters or safety warnings for the imported text.
- Capability inventory: The skill acts as a dispatcher for workflow management, implying access to file system operations and potentially shell tools through the loaded sub-prompts.
- Sanitization: Absent; the skill relies on the integrity of the remote repository content.
Audit Metadata