hexabot-workflow-writer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of Markdown documentation and YAML examples for the Hexabot v3 platform. It does not execute malicious commands or exfiltrate data.
- [SAFE]: The documentation emphasizes security best practices, such as excluding secrets from YAML and checking for prompt injection in generated workflows.
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted business use cases as input (Ingestion: SKILL.md). It mitigates risk by instructing the agent to use delimiters (Boundary: Authoring Guide), perform validation (Sanitization: Review Checklist), and use standard coding agent tools (Capability: SKILL.md).
- [SAFE]: External references in examples point to well-known technology companies or local services, following the trusted vendor pattern for hexabot-ai.
Audit Metadata