workflow-analyze
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes strong directives such as 'MUST' and 'CRITICAL' to enforce its documentation standards and anti-bias rules. These are instructional constraints for the specific task and do not attempt to bypass core safety protocols or override general agent behavior.
- [DATA_EXFILTRATION]: No network operations or access to sensitive file paths were found. The skill reads user-provided arguments and writes local markdown files to a specific project subdirectory.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input through the '$ARGUMENTS' variable. This input is used to generate the task definition and analysis content. The capability is restricted to creating markdown documentation, which minimizes risk. Ingestion point: $ARGUMENTS variable in SKILL.md. Boundary markers: None explicitly defined. Capability inventory: File writing to 'docs/work/' directory. Sanitization: Not specified.
Audit Metadata