workflow-housekeep

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill is designed to search for and read potentially sensitive files such as .env, .env.local, and .env.production. While the stated intent is to audit for committed secrets and verify environment variable examples, reading these files exposes sensitive configuration and credentials to the agent context.
  • [COMMAND_EXECUTION]: The skill executes various system and package manager commands including rm for file deletion and package-specific update commands like npm update, cargo update, or go get. It also interacts with the project's version control system to verify history.
  • [DYNAMIC_EXECUTION]: The skill runs project-specific scripts such as npm run build, npm run lint, and npm test to verify project stability after dependency updates. Since the contents of these scripts are defined within the target repository's manifest (e.g., package.json), the agent is executing code that is dynamically determined by the project environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from repository files and external web search results to automate documentation and updates, creating a surface for indirect instructions.
  • Ingestion points: Project manifest files, READMEs, source code files, and external web content retrieved via firecrawl_search.
  • Boundary markers: No specific delimiters or safety instructions are defined to separate ingested data from the agent's core instructions.
  • Capability inventory: Includes file system deletion (rm), dependency installation/updates, and execution of arbitrary project scripts.
  • Sanitization: There are no verification or sanitization steps mentioned for data retrieved from external searches or existing project files.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to download and execute utility packages such as knip, ts-prune, and npm-check-updates from the npm registry. It also performs external web searches using the Firecrawl service to find library migration guides.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — workflow-housekeep