workflow
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative overrides such as "CRITICAL: Always Use Correct documentation" and "Your knowledge is outdated" to bypass the agent's internal training and force adherence to the provided instructions.
- [METADATA_POISONING]: The skill metadata falsely claims the author is "Vercel Inc.", contradicting the actual author identity "LucasDuarteInacio". This impersonation is a deceptive technique used to gain trust.
- [UNVERIFIABLE_DEPENDENCIES]: The skill promotes the installation of the 'workflow' and '@workflow/*' packages. Official Vercel tools use the '@vercel' scope; the 'workflow' package on npm is unrelated to Vercel, representing a significant supply chain risk.
- [COMMAND_EXECUTION]: The skill instructs the agent to run 'npx workflow' commands. This utility downloads and executes code from the unverified 'workflow' npm package, which could contain malicious payloads.
- [DYNAMIC_EXECUTION]: The documentation encourages moving logic into 'step' functions that have 'full Node.js and npm access' to bypass sandbox restrictions. In the context of the promoted untrusted dependencies, this provides a clear path for privilege escalation and system compromise.
Recommendations
- AI detected serious security threats
Audit Metadata