flow-designer
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns detected. The skill provides clear instructions for using ServiceNow's Flow Designer tools and adheres to the platform's architectural best practices.
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates for script actions that process external data without demonstrating specific sanitization steps, representing a standard platform integration surface.
- Ingestion points: Custom action inputs, trigger data, and REST API response bodies (SKILL.md).
- Boundary markers: Absent in the provided code snippets (SKILL.md).
- Capability inventory: The skill interacts with the ServiceNow instance using snow_execute_script and snow_query_table tools (SKILL.md).
- Sanitization: Absent in the provided JavaScript snippets (SKILL.md).
Audit Metadata