restate-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of the
joelclawcommand-line interface to submit workload artifacts and emit queue events. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data in the form of task descriptions and prompts which are subsequently processed by a background runner.
- Ingestion points: The
task.promptfield within the JSON request payload inSKILL.mdserves as a primary input point for untrusted content. - Boundary markers: The skill uses a structured JSON schema to delimit task data.
- Capability inventory: The skill provides functionality to invoke the
joelclawCLI via shell execution as seen in the provided Node.js example inSKILL.md. - Sanitization: The code examples utilize
JSON.stringifyto escape payload contents before they are passed as arguments to thespawnfunction. - [DYNAMIC_EXECUTION]: The skill provides a boilerplate implementation using
node:child_process.spawnto dynamically construct and execute shell commands based on runtime input.
Audit Metadata