workflow-devkit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's documentation and templates for AI-driven RAG (Retrieval-Augmented Generation) patterns contain a vulnerability surface for SQL injection. In
ai-integration.mdandpatterns.md, thesearchDatabasetool implementation demonstrates unsafe string interpolation of AI-generated inputs into raw database queries:db.query(`SELECT * FROM knowledge WHERE content LIKE '%${query}%'`). This pattern lacks proper parameterization or sanitization, creating a risk where a malicious prompt could influence the AI to generate inputs that execute unintended SQL commands. - Ingestion points: The
queryparameter provided to thesearchDatabasetool inai-integration.mdandpatterns.md. - Boundary markers: Absent; the tool input is directly embedded into the SQL string template.
- Capability inventory: The skill examples utilize database query execution via
db.query. - Sanitization: Absent; the examples use template literals instead of parameterized queries or a type-safe ORM layer for the search logic.
- [EXTERNAL_DOWNLOADS]: The skill requires several Node.js packages for installation, including
workflowand@workflow/ai. These are niche or framework-specific dependencies that are not standard public libraries. While they align with the vendor's 'Workflow DevKit' project, they represent a reliance on unverifiable external code sources.
Audit Metadata