ai-automation-workflows

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The 'Data Processing Pipeline' example demonstrates a surface for indirect prompt injection.
  • Ingestion points: Local text files read via cat in data_processing.sh.
  • Boundary markers: Absent; file content is directly concatenated into the model prompt string.
  • Capability inventory: Scripts perform file system operations (read/write) and execute CLI tools via Bash and Python subprocesses.
  • Sanitization: None; the content of the processed files is used raw without validation or escaping.
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install external tools and dependencies, including the belt-sh/cli via npx and other skills from the inference-sh repository.
  • [COMMAND_EXECUTION]: The skill uses extensive shell scripting and Python subprocess.run to execute commands, create directories, and manage local files as part of the automation workflows.
  • [DATA_EXFILTRATION]: Includes a 'Monitoring and Logging' template that uses curl to transmit execution data and error logs to an external webhook provider (https://your-webhook.com/alert).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:22 AM
Security Audit — agent-trust-hub — ai-automation-workflows