workflow-run
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill invokes JavaScript orchestration scripts stored in the
.claude/workflows/directory and supports resuming workflows from run IDs, which involves dynamic loading of state and code execution. - [COMMAND_EXECUTION]: The skill uses the
Bashtool and specializedrufloworkflow tools (e.g.,mcp__plugin_ruflo-core_ruflo__workflow_execute) to manage lifecycle operations and execute system-level commands. - [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: Reads workflow definitions and orchestration scripts from the
.claude/workflows/directory and accepts arguments for those scripts. 2. Boundary markers: The instructions do not define delimiters or specific warnings to prevent the agent from following instructions embedded within the workflow data. 3. Capability inventory: The skill has access to high-privilege tools includingBashand the JavaScriptWorkflowrunner. 4. Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the scripts or arguments before execution.
Audit Metadata