windsurf-flows-automation

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of documentation and templates for creating automation workflows. All referenced links point to official documentation (windsurf.ai) or the author's professional infrastructure (tonsofskills.com, intentsolutions.io, jeremylongshore.com), which is consistent with the skill's stated purpose and identity.
  • [INDIRECT_PROMPT_INJECTION]: Analysis of the attack surface identifies that the skill ingests user input for flow creation (identified in SKILL.md) and utilizes the Bash, Write, and Edit tools to generate and execute operations. While the provided reference files do not specify explicit boundary markers or sanitization logic, this is consistent with the skill's role as a developer-oriented automation framework, and no malicious exploitation patterns were observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:48 AM
Security Audit — agent-trust-hub — windsurf-flows-automation