blueprint

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs dynamic code generation as part of its 'Project Mode' logic. It instructs the agent to embed data literals directly into the scripts/draw_workflow.js template, save the resulting script to a file, and then execute it via the platform's Workflow API.
  • [COMMAND_EXECUTION]: Python utilities within the skill (scripts/freshness.py and scripts/stamp_provenance.py) use subprocess.run to execute Git shell commands. This capability is used to baseline repository state and detect modified files to avoid redundant rendering.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it utilizes sub-agents to analyze untrusted source code within a target repository.
  • Ingestion points: The enumerate-prompt.md and scenario-prompt.md instructions require agents to read and interpret the project's source code and configuration files.
  • Boundary markers: Absent; the prompts do not use specific delimiters or escape sequences to isolate analyzed code from the agent's instructions.
  • Capability inventory: The skill can execute shell commands (git) and launch dynamic workflow scripts.
  • Sanitization: Not present; values extracted from the codebase are baked directly into generated scripts as literals.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — blueprint