use-workflow

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains standard instructional guidelines for task routing and prioritization. No patterns attempting to bypass safety filters or override core agent behavior were identified.
  • [DATA_EXFILTRATION]: No network operations, credential harvesting, or access to sensitive local environment files (e.g., .ssh, .aws) were found.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any external downloads or execute remote scripts. It contains no package dependencies or dynamic code execution patterns.
  • [OBFUSCATION]: All analyzed files (SKILL.md, references, and configurations) are written in plain text. No Base64, zero-width characters, or other encoding techniques were used to hide content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to incorporate 'repo-local instructions' and a 'repo Glossary' into its decision-making process. While this represents a surface where external data enters the agent's context, it is the primary intended function of the workflow router and no dangerous capabilities were identified in the associated scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 03:47 AM
Security Audit — agent-trust-hub — use-workflow