build-flow

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • User Input Interpolation: The skill uses the $ARGUMENTS placeholder to receive flow descriptions from the user. This is an area to review as external input is processed directly alongside core agent instructions, which is a common surface for indirect prompt injection where a user might attempt to override established rules.
  • Resource Management Capabilities: The skill utilizes specialized MCP tools to manage cloud environments, connections, and flows. These administrative capabilities are required to fulfill the primary goal of creating, configuring, and publishing Power Automate flows autonomously.
  • Local Environment Interaction: The skill has access to shell and file system tools such as Bash, Write, and Read. This access is intended for local tasks such as generating flow definition files and validating JSON structures before they are sent to the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 10:56 AM
Security Audit — agent-trust-hub — build-flow