workflow-rig

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands, specifically through a shell handler within a restate-worker environment. It includes built-in support for repository management tasks such as git clone, git commit, and git push.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources which could theoretically contain instructions intended to influence the agent.
  • Ingestion points: External JSON files loaded via the --stages-from flag and user-provided intent strings.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" warnings for the content of the stages JSON.
  • Capability inventory: The environment possesses high-privilege capabilities including arbitrary shell execution, Git repository modification, and automated file editing via the infer tool.
  • Sanitization: The skill documentation focus on validation of DAG structure (cycles, duplicate IDs) rather than content sanitization of the data fields.
  • [DYNAMIC_EXECUTION]: The workflow engine uses runtime string interpolation (e.g., {{nodeId}}) to pass data between execution stages, which dynamically assembles the context for downstream commands and agent instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — workflow-rig