workflow-creator
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a Python script (
scripts/download_skill.py) to clone external GitHub repositories to download new agent skills. While many curated sources are provided inreferences/skill-sources.md, the tool supports downloading from any user-provided URL. - [COMMAND_EXECUTION]: The skill executes system commands via
subprocess.runto callgitfor cloning repositories and managing sparse checkouts within thescripts/download_skill.pyfile. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and organize external agent instructions (
SKILL.mdfiles) from untrusted sources, creating a surface for indirect instruction injection. - Ingestion points: Repository URLs and skill paths processed by
scripts/download_skill.pyin the root and specified output directories. - Boundary markers: Absent; the system does not wrap downloaded instructions in security delimiters or provide "ignore" directives for embedded content.
- Capability inventory: The skill performs directory creation, symlink management, and file writing (
shutil.copytree) across various AI tool configuration folders (e.g.,.claude/skills,.cursor/skills). - Sanitization: No validation or sanitization of the content within the downloaded skills is performed beyond checking for the existence of a
SKILL.mdfile.
Audit Metadata