nat-workflow-creation
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of agents that process user-supplied input through the
nat run --inputcommand, which represents a surface for indirect prompt injection. - Ingestion points: User queries provided via the
--inputor--input_fileflags as described inSKILL.mdandreferences/cli-reference.md. - Boundary markers: The toolkit uses YAML-based configuration schemas (e.g.,
functions,llms,workflow) to separate agent definitions from runtime execution data. - Capability inventory: The agent can execute registered functions (tools) and interact with LLM providers as detailed in
references/workflow-creation.mdandreferences/llm-config.md. - Sanitization: The documentation focuses on CLI usage and configuration scaffolding; explicit input sanitization or output validation mechanisms are not detailed within these references, relying instead on the underlying toolkit's implementation.
Audit Metadata