workflow-refactor
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted content from the web via the
firecrawl:firecrawl_scrapetool to research coding patterns. - Ingestion points: The output of
firecrawl:firecrawl_scrapedescribed inSKILL.md. - Boundary markers: None identified; the instructions do not include delimiters or warnings to ignore instructions embedded in the scraped content.
- Capability inventory: The skill includes instructions to modify source code (file system writes) and execute shell commands (running tests and using
rg). - Sanitization: No sanitization or validation of the scraped web content is specified before the agent processes it.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
rg(Ripgrep) to map the blast radius and find dependencies within the local codebase.
Audit Metadata