workflow-rig
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands, specifically through a
shellhandler within arestate-workerenvironment. It includes built-in support for repository management tasks such asgit clone,git commit, andgit push. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources which could theoretically contain instructions intended to influence the agent.
- Ingestion points: External JSON files loaded via the
--stages-fromflag and user-provided intent strings. - Boundary markers: The instructions do not define specific delimiters or "ignore" warnings for the content of the stages JSON.
- Capability inventory: The environment possesses high-privilege capabilities including arbitrary shell execution, Git repository modification, and automated file editing via the
infertool. - Sanitization: The skill documentation focus on validation of DAG structure (cycles, duplicate IDs) rather than content sanitization of the data fields.
- [DYNAMIC_EXECUTION]: The workflow engine uses runtime string interpolation (e.g.,
{{nodeId}}) to pass data between execution stages, which dynamically assembles the context for downstream commands and agent instructions.
Audit Metadata