workflow-refactor

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted content from the web via the firecrawl:firecrawl_scrape tool to research coding patterns.
  • Ingestion points: The output of firecrawl:firecrawl_scrape described in SKILL.md.
  • Boundary markers: None identified; the instructions do not include delimiters or warnings to ignore instructions embedded in the scraped content.
  • Capability inventory: The skill includes instructions to modify source code (file system writes) and execute shell commands (running tests and using rg).
  • Sanitization: No sanitization or validation of the scraped web content is specified before the agent processes it.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using rg (Ripgrep) to map the blast radius and find dependencies within the local codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — workflow-refactor