workflow-creation

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a secure environment for video workflow creation by leveraging platform-validated tools and requiring human-in-the-loop approval for critical operations.
  • [PROMPT_INJECTION]: The skill effectively manages the indirect prompt injection surface involved in script-to-video generation. Evidence chain: 1) Ingestion points include user scripts and reference assets; 2) Boundary markers are implemented through the Three-Judge Frame and Internal Quality Gate; 3) Capabilities are limited to specific workflow management tools; 4) Sanitization is managed via Sidecar Guardrails that diagnose and repair generation risks.
  • [DATA_EXFILTRATION]: All data operations are restricted to the vendor's platform APIs and CLI. No unauthorized access to sensitive local files or data exfiltration to third-party domains was observed.
  • [COMMAND_EXECUTION]: Use of the postplus CLI is confined to platform-specific operations with mandatory validation and human confirmation steps, preventing arbitrary shell command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 03:43 PM
Security Audit — agent-trust-hub — workflow-creation