workflow-create
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill facilitates the authoring of imperative orchestration scripts in
.claude/workflows/*.js. It provides a specific procedure to validate these scripts by reading the file content, wrapping it in an asynchronous execution context, and performing a syntax check usingnode --check. - [INDIRECT_PROMPT_INJECTION]: The skill defines a framework where authored workflows can spawn subagents using an
agent()hook. This creates a vulnerability surface where data processed by the workflow could contain instructions that influence subagent behavior. - Ingestion points: Data passed as prompts or options to the
agent(prompt, opts)function within authored scripts (SKILL.md). - Boundary markers: None identified; there are no instructions for using delimiters or warnings to ignore embedded instructions in the subagent prompts.
- Capability inventory: The skill and its associated workflows have access to tools including
Write,Read,Edit, andBash(SKILL.md frontmatter). - Sanitization: The skill does not describe or enforce sanitization of the input passed to subagents or the structured output returned by them.
- [COMMAND_EXECUTION]: The documentation includes a Bash one-liner that uses
node -eto perform file system operations (fs.readFileSync,fs.writeFileSync) to transform authored scripts into a format suitable for syntax verification.
Audit Metadata