blueprint
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs dynamic code generation as part of its 'Project Mode' logic. It instructs the agent to embed data literals directly into the
scripts/draw_workflow.jstemplate, save the resulting script to a file, and then execute it via the platform's Workflow API. - [COMMAND_EXECUTION]: Python utilities within the skill (
scripts/freshness.pyandscripts/stamp_provenance.py) usesubprocess.runto execute Git shell commands. This capability is used to baseline repository state and detect modified files to avoid redundant rendering. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it utilizes sub-agents to analyze untrusted source code within a target repository.
- Ingestion points: The
enumerate-prompt.mdandscenario-prompt.mdinstructions require agents to read and interpret the project's source code and configuration files. - Boundary markers: Absent; the prompts do not use specific delimiters or escape sequences to isolate analyzed code from the agent's instructions.
- Capability inventory: The skill can execute shell commands (git) and launch dynamic workflow scripts.
- Sanitization: Not present; values extracted from the codebase are baked directly into generated scripts as literals.
Audit Metadata