temporal-ops

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external worker logs and command-line outputs to perform layer-by-layer diagnostics.
  • Ingestion points: Worker logs (referenced in SKILL.md and references/triage/worker-health.md) and copy-pasted CLI error strings are used as primary data sources for troubleshooting.
  • Boundary markers: Instructions do not provide explicit delimiters or "ignore instructions" wrappers for the ingested log content, relying on standard gRPC error prefixes for classification.
  • Capability inventory: The skill utilizes administrative CLI tools (temporal, tcld) with capabilities for destructive operations such as namespace deletion and workflow termination (SKILL.md, references/ops/cloud-namespace-admin.md).
  • Sanitization: No explicit sanitization or filtering logic is prescribed for the external log data before it enters the agent context.
  • [EXTERNAL_DOWNLOADS]: The skill refers to and provides instructions for downloading vendor-provided tools and dependencies from trusted infrastructure.
  • Fetches the Temporal and Temporal Cloud CLI tools via the Homebrew package manager (SKILL.md).
  • References official Temporal repositories on GitHub for Cloud API definitions and SDK samples (references/ops/cloud-ops-api.md).
  • Downloads AWS CloudFormation templates for audit log integration from a vendor-managed S3 bucket (references/ops/cloud-audit-logs.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:00 AM