agentic-workflows

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch prompt files and sub-skills from the github/gh-aw repository. These resources are hosted on a well-known service and are owned by the official author, representing the primary intended functionality of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files to determine agent behavior, creating a surface for indirect prompt injection.
  • Ingestion points: Files under .github/aw/ and .github/skills/ within the github/gh-aw repository (SKILL.md).
  • Boundary markers: Absent; the skill follows the loaded content directly without explicit delimiters or safety warnings for the imported text.
  • Capability inventory: The skill acts as a dispatcher for workflow management, implying access to file system operations and potentially shell tools through the loaded sub-prompts.
  • Sanitization: Absent; the skill relies on the integrity of the remote repository content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 09:21 PM
Security Audit — agent-trust-hub — agentic-workflows