rivet-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements workflow logic that ingests and processes data from external sources, which constitutes a surface for indirect prompt injection.
- Ingestion points: Data is received from messaging queues using
ctx.queue.next()andloopCtx.queue.nextBatch(), as well as from external APIs viafetch()calls across several files includingapproval-gate.ts,batch-drainer.ts, andfan-in-out.ts. - Boundary markers: The code lacks explicit boundary markers or instructions to isolate or ignore potentially malicious instructions embedded in the ingested data.
- Capability inventory: The skill has the capability to perform network operations and modify persistent workflow state through its core APIs.
- Sanitization: There is no evidence of input validation or sanitization being applied to external data before it is used to drive workflow logic.
- [DATA_EXFILTRATION]: The skill performs network requests to external domains not included in the standard whitelist.
- Evidence: Multiple example files such as
approval-gate.ts,fan-in-out.ts, andsetup-teardown/index.tsuse thefetchAPI to communicate withapi.example.comandapi.stripe.com.
Audit Metadata