cli-anything-dify-workflow
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download and install a package from a third-party personal GitHub repository (github.com/Akabane71/dify-workflow-cli). This source is not an official organization or a recognized trusted vendor.
- [REMOTE_CODE_EXECUTION]: The installation instructions utilize
pip installto fetch and install code from a remote Git repository, which is then executed when the CLI commands are invoked. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as YAML and JSON workflow configurations.
- Ingestion points: The skill reads and processes Dify workflow files (e.g.,
workflow.yaml,app.yaml) via theinspect,validate, andeditcommands inSKILL.md. - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious content embedded within these data files.
- Capability inventory: The skill allows for local file modification (
create,edit), inspection, and execution of a CLI wrapper, as described inSKILL.md. - Sanitization: There is no evidence of sanitization or validation of the content within the YAML/JSON files before the data is processed or presented to the agent.
Audit Metadata