ai-automation-workflows
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The 'Data Processing Pipeline' example demonstrates a surface for indirect prompt injection.
- Ingestion points: Local text files read via
catindata_processing.sh. - Boundary markers: Absent; file content is directly concatenated into the model prompt string.
- Capability inventory: Scripts perform file system operations (read/write) and execute CLI tools via Bash and Python subprocesses.
- Sanitization: None; the content of the processed files is used raw without validation or escaping.
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install external tools and dependencies, including the
belt-sh/clivia npx and other skills from theinference-shrepository. - [COMMAND_EXECUTION]: The skill uses extensive shell scripting and Python
subprocess.runto execute commands, create directories, and manage local files as part of the automation workflows. - [DATA_EXFILTRATION]: Includes a 'Monitoring and Logging' template that uses
curlto transmit execution data and error logs to an external webhook provider (https://your-webhook.com/alert).
Audit Metadata