workflow-audit
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely on local files to perform its intended auditing function. While it interacts with data from other skills, it does not demonstrate any suspicious patterns.
- [PROMPT_INJECTION]: The skill processes content from other skill directories (such as
SKILL.mdandtask.md) to conduct audits, which creates a surface for indirect prompt injection. However, the risk is limited to the skill's specific capabilities of creating or moving local files within the project structure, and no explicit injection or safety bypasses were found. - Ingestion points: Reads skill definitions and output files from the local filesystem (Step 2).
- Boundary markers: The instructions do not define specific delimiters for separating audited content from the auditor's instructions.
- Capability inventory: File reading, creation of audit reports (Step 5), and file system organization/link updating (Step 6).
- Sanitization: No content sanitization is specified for the data being audited.
Audit Metadata