workflow-creator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses a Python script (scripts/download_skill.py) to clone external GitHub repositories to download new agent skills. While many curated sources are provided in references/skill-sources.md, the tool supports downloading from any user-provided URL.
  • [COMMAND_EXECUTION]: The skill executes system commands via subprocess.run to call git for cloning repositories and managing sparse checkouts within the scripts/download_skill.py file.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and organize external agent instructions (SKILL.md files) from untrusted sources, creating a surface for indirect instruction injection.
  • Ingestion points: Repository URLs and skill paths processed by scripts/download_skill.py in the root and specified output directories.
  • Boundary markers: Absent; the system does not wrap downloaded instructions in security delimiters or provide "ignore" directives for embedded content.
  • Capability inventory: The skill performs directory creation, symlink management, and file writing (shutil.copytree) across various AI tool configuration folders (e.g., .claude/skills, .cursor/skills).
  • Sanitization: No validation or sanitization of the content within the downloaded skills is performed beyond checking for the existence of a SKILL.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — workflow-creator