restate-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the joelclaw command-line interface to submit workload artifacts and emit queue events.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data in the form of task descriptions and prompts which are subsequently processed by a background runner.
  • Ingestion points: The task.prompt field within the JSON request payload in SKILL.md serves as a primary input point for untrusted content.
  • Boundary markers: The skill uses a structured JSON schema to delimit task data.
  • Capability inventory: The skill provides functionality to invoke the joelclaw CLI via shell execution as seen in the provided Node.js example in SKILL.md.
  • Sanitization: The code examples utilize JSON.stringify to escape payload contents before they are passed as arguments to the spawn function.
  • [DYNAMIC_EXECUTION]: The skill provides a boilerplate implementation using node:child_process.spawn to dynamically construct and execute shell commands based on runtime input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — restate-workflows