workhuman-upgrade-migration
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
WebFetchtool to retrieve current integration capabilities and security/privacy guidelines from Workhuman's official documentation domains. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it is designed to process external, potentially untrusted configuration data.
- Ingestion points: The skill reads external customer-authorized contracts, schemas, and implementation artifacts using
Read,Glob, andWebFetch. - Boundary markers: The instructions do not define specific delimiters to separate external data from the agent's core instructions.
- Capability inventory: The agent has the ability to use
WriteandEdittools to generate compatibility code and migration plans based on the ingested artifacts. - Sanitization: The instructions do not explicitly mandate sanitization of the input data before it is processed by the agent.
- Mitigation: The risk is effectively mitigated by strict "Approval Boundaries" which mandate that no production traffic, worker data, or connector changes can be executed without approval from accountable owners.
Audit Metadata