workflow-feature-flag

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured workflow for feature flag management, including detection, design, implementation, and cleanup phases, all following industry standard practices.- [DATA_EXPOSURE]: Sensitive information such as API keys and organization identifiers are handled using placeholders (e.g., , <PROJECT_ID>) and environment variable references, which is a safe practice.- [SAFE]: External tool integrations, specifically the use of Sentry for issue analysis and Supabase for log retrieval, are restricted to monitoring performance and error rates during rollouts.- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data sources such as Sentry issues and Supabase logs. While this represents a potential ingestion surface for indirect prompt injection, it is a standard and necessary component for the skill's primary monitoring purpose and carries low inherent risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:56 AM
Security Audit — agent-trust-hub — workflow-feature-flag