manage-flows
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill processes external data including flow names and execution logs, which are ingested via tools such as
mcp__flowagent__list_flowsandmcp__flowagent__get_run_historyin SKILL.md. This data is utilized alongside management capabilities likemcp__flowagent__delete_flowandmcp__flowagent__cancel_all_runsalso defined in SKILL.md. The absence of explicit boundary markers or data sanitization steps when handling these external inputs represents a potential surface where malformed data could attempt to influence the agent's instructions, though this is a common characteristic of data-intensive management skills.
Audit Metadata