workday-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill contains an implementation example that ingests and processes data from an external API service.\n
- Ingestion points: The
WorkdayAPI.get_workersmethod inreferences/EXAMPLES.mdretrieves worker data via REST API calls from a Workday service domain.\n - Boundary markers: The implementation does not use explicit delimiters or instructions to treat the returned XML data as untrusted content.\n
- Capability inventory: The skill is configured with
Read,Write,Bash, andWebSearchtools, allowing the agent to perform follow-up actions with ingested data.\n - Sanitization: The Python example parses XML using the
ElementTreelibrary but lacks specific sanitization or validation logic for the data fields before they are processed by the agent.
Audit Metadata