build-flow
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- User Input Interpolation: The skill uses the
$ARGUMENTSplaceholder to receive flow descriptions from the user. This is an area to review as external input is processed directly alongside core agent instructions, which is a common surface for indirect prompt injection where a user might attempt to override established rules. - Resource Management Capabilities: The skill utilizes specialized MCP tools to manage cloud environments, connections, and flows. These administrative capabilities are required to fulfill the primary goal of creating, configuring, and publishing Power Automate flows autonomously.
- Local Environment Interaction: The skill has access to shell and file system tools such as
Bash,Write, andRead. This access is intended for local tasks such as generating flow definition files and validating JSON structures before they are sent to the API.
Audit Metadata