nat-workflow-creation

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of agents that process user-supplied input through the nat run --input command, which represents a surface for indirect prompt injection.
  • Ingestion points: User queries provided via the --input or --input_file flags as described in SKILL.md and references/cli-reference.md.
  • Boundary markers: The toolkit uses YAML-based configuration schemas (e.g., functions, llms, workflow) to separate agent definitions from runtime execution data.
  • Capability inventory: The agent can execute registered functions (tools) and interact with LLM providers as detailed in references/workflow-creation.md and references/llm-config.md.
  • Sanitization: The documentation focuses on CLI usage and configuration scaffolding; explicit input sanitization or output validation mechanisms are not detailed within these references, relying instead on the underlying toolkit's implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — nat-workflow-creation