workhuman-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill incorporates robust governance by establishing clear approval boundaries for sensitive actions such as fund spending, award level modifications, and eligibility changes.- [SAFE]: Privacy best practices are explicitly mandated through instructions for data redaction and the exclusion of sensitive information from receipts and logs.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external program briefs and audience rosters, creating a potential attack surface for indirect prompt injection.
  • Ingestion points: Arguments [program-brief] and [audience], and roster data accessed via the Read tool.
  • Boundary markers: The skill instructs the agent to 'Freeze purpose' and 'Validate message policy' before execution, creating logical checkpoints.
  • Capability inventory: The skill utilizes Read, WebFetch, Write, and Edit tools to interact with the environment.
  • Sanitization: The instructions require 'sensitive-data exclusions' and the production of 'redacted receipts' to mitigate data leakage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 AM
Security Audit — agent-trust-hub — workhuman-core-workflow-a