cli-anything-dify-workflow

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download and install a package from a third-party personal GitHub repository (github.com/Akabane71/dify-workflow-cli). This source is not an official organization or a recognized trusted vendor.
  • [REMOTE_CODE_EXECUTION]: The installation instructions utilize pip install to fetch and install code from a remote Git repository, which is then executed when the CLI commands are invoked.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as YAML and JSON workflow configurations.
  • Ingestion points: The skill reads and processes Dify workflow files (e.g., workflow.yaml, app.yaml) via the inspect, validate, and edit commands in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content embedded within these data files.
  • Capability inventory: The skill allows for local file modification (create, edit), inspection, and execution of a CLI wrapper, as described in SKILL.md.
  • Sanitization: There is no evidence of sanitization or validation of the content within the YAML/JSON files before the data is processed or presented to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-dify-workflow