workhuman-webhooks-events

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle external data from Workhuman APIs and webhook events. This represents an attack surface for indirect prompt injection if external payloads contain malicious instructions. However, the skill provides specific instructions to mitigate this, such as implementing 'validate-before-acknowledge' logic, quarantine procedures for failed authenticity checks, and reconciliation against authoritative sources (SKILL.md).
  • [COMMAND_EXECUTION]: The skill references the use of standard development tools like Read, Write, and Edit to build and maintain ingestion code. The instructions require that any mutation of records or deployment of endpoints involve a named owner and explicit approval, reducing the risk of unauthorized command execution (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: The skill references official Workhuman documentation and blog posts for integration guidance. These are well-known and trusted service domains (workhuman.com) used for legitimate configuration reference (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:04 AM
Security Audit — agent-trust-hub — workhuman-webhooks-events