designing-workflow-skills

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and documentation-based, providing guidance on how to structure other skills using specific workflow patterns (Routing, Pipeline, Linear, Safety Gate, and Task-Driven).
  • [SAFE]: It actively promotes security and reliability best practices through an anti-patterns catalog (e.g., AP-4 warns against hardcoded paths, AP-12 promotes the Principle of Least Privilege, and AP-8 requires verification steps).
  • [SAFE]: The tool configuration (allowed-tools) is restricted to read-only and task-management tools (Read, Glob, Grep, TodoRead, TodoWrite), which is appropriate for its stated purpose.
  • [SAFE]: While the skill documents platform features such as shell preprocessing (!command syntax) and variable substitution, it does so to warn developers about potential accidental execution and to guide proper implementation of dynamic context. It does not execute any dangerous commands itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:19 PM
Security Audit — agent-trust-hub — designing-workflow-skills