workflow-designer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as an instructional template for designing workflow specifications. It guides the agent to identify triggers, inputs, and states without performing unauthorized network operations, credential access, or privilege escalation.- [INDIRECT_PROMPT_INJECTION]: The skill involves processing existing repository data to generate documentation, which is a potential surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: Processes existing SOPs, scripts, CI configurations, and issue templates (Step 1 in SKILL.md).
  • Boundary markers: No explicit delimiting or instructions to ignore embedded commands are defined.
  • Capability inventory: The skill facilitates file reading and writing specifications to the workflows/ directory.
  • Sanitization: The skill does not specify sanitization or validation of the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:18 PM
Security Audit — agent-trust-hub — workflow-designer