uipath-maestro-bpmn

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install or update the official vendor CLI tool (@uipath/cli) using the npm or bun package managers. These downloads originate from well-known, official package registries and are necessary for the skill's core functionality.
  • [COMMAND_EXECUTION]: The skill extensively utilizes the Bash tool to execute uip CLI commands for local project management and cloud-based orchestration. These operations include resource discovery, project validation, and process lifecycle management. The skill explicitly mandates that the agent must obtain user consent via the AskUserQuestion tool before performing any mutations or running instances in the cloud.
  • [DATA_EXFILTRATION]: To prevent the exposure of sensitive data, the skill includes a dedicated reference (references/public-safety.md) that defines strict redaction policies. These rules require the agent to replace tenant URLs, folder keys, and authentication secrets with placeholders, ensuring that generated artifacts and summaries remain safe for public use.
  • [SAFE]: The skill authors BPMN XML containing embedded JavaScript for scriptTask nodes. These scripts are executed in a sandboxed 'Jint' runtime on the UiPath platform, which lacks access to the host's filesystem or network, effectively mitigating risks associated with arbitrary code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:12 PM
Security Audit — agent-trust-hub — uipath-maestro-bpmn