software-workflow-automation

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/replay_dlq.py includes functionality to execute system commands based on a user-provided template. The implementation uses the safe list-based subprocess.run method to avoid shell injection vulnerabilities and is provided as a legitimate utility for replaying messages from dead-letter queues. The default command is a benign echo statement.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it processes external JSON files through scripts/check_workflow_idempotency.py and scripts/replay_dlq.py.
  • Ingestion points: Local JSON input files processed by Python scripts.
  • Boundary markers: None present in the data processing scripts to distinguish data from instructions.
  • Capability inventory: Command execution via subprocess.run is available in replay_dlq.py.
  • Sanitization: The scripts use standard JSON deserialization and do not pass content directly into a large language model's instruction context, which mitigates the risk of the agent accidentally following instructions embedded within the JSON data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-workflow-automation