workhuman-core-workflow-b

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong defensive measures for handling sensitive HR and payroll data, such as requiring explicit owner approval for modifications, using synthetic fixtures for testing, and prohibiting automatic correction of financial discrepancies.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection because it ingests external integration claims via WebFetch and local reports using Read. This risk is effectively mitigated by the instructions requiring manual data classification, human review checkpoints, and the production of redacted receipts to prevent the leakage of sensitive data into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:05 AM
Security Audit — agent-trust-hub — workhuman-core-workflow-b