workflow-devkit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's documentation and templates for AI-driven RAG (Retrieval-Augmented Generation) patterns contain a vulnerability surface for SQL injection. In ai-integration.md and patterns.md, the searchDatabase tool implementation demonstrates unsafe string interpolation of AI-generated inputs into raw database queries: db.query(`SELECT * FROM knowledge WHERE content LIKE '%${query}%'`). This pattern lacks proper parameterization or sanitization, creating a risk where a malicious prompt could influence the AI to generate inputs that execute unintended SQL commands.
  • Ingestion points: The query parameter provided to the searchDatabase tool in ai-integration.md and patterns.md.
  • Boundary markers: Absent; the tool input is directly embedded into the SQL string template.
  • Capability inventory: The skill examples utilize database query execution via db.query.
  • Sanitization: Absent; the examples use template literals instead of parameterized queries or a type-safe ORM layer for the search logic.
  • [EXTERNAL_DOWNLOADS]: The skill requires several Node.js packages for installation, including workflow and @workflow/ai. These are niche or framework-specific dependencies that are not standard public libraries. While they align with the vendor's 'Workflow DevKit' project, they represent a reliance on unverifiable external code sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — workflow-devkit