workflow-creator
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell commands such as
ls,grep, andtest, and executes project-resident scripts likevalidate-integration.cjsandduplicate-detector.cjsto manage project state and verify the integration of new workflows. - [EXTERNAL_DOWNLOADS]: The skill fetches data from arXiv.org and performs web searches via Exa to research industry standards and orchestration patterns. These references target reputable academic and information services and do not involve the execution of remote code.
- [INDIRECT_PROMPT_INJECTION]: The skill generates instructions for sub-agents by creating workflow files and task prompts based on user input, which creates a potential surface for indirect influence.
- Ingestion points: User-provided workflow names, descriptions, and agent role assignments.
- Boundary markers: The generated prompts use markdown structures and headers to organize instructions, though they lack explicit isolation markers to prevent user-supplied descriptions from overriding system instructions.
- Capability inventory: The skill can write new markdown files to the
.claude/workflows/directory, update project configuration inCLAUDE.md, and initiateTask()spawns for new agents. - Sanitization: Filenames are sanitized to alphanumeric characters and hyphens, and the keyword generation script uses
JSON.stringifyto ensure that user-provided text does not break configuration file syntax. - [DYNAMIC_EXECUTION]: The skill programmatically updates local Javascript configuration files, specifically
routing-table-intent-keywords.cjsandrouting-table-intent-agents.cjs, by appending new entries to export objects. While these modifications are structured and use fixed insertion points, the modification of executable files at runtime is a privileged operation used for system integration.
Audit Metadata