software-workflow-automation
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/replay_dlq.pyincludes functionality to execute system commands based on a user-provided template. The implementation uses the safe list-basedsubprocess.runmethod to avoid shell injection vulnerabilities and is provided as a legitimate utility for replaying messages from dead-letter queues. The default command is a benignechostatement. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it processes external JSON files through
scripts/check_workflow_idempotency.pyandscripts/replay_dlq.py. - Ingestion points: Local JSON input files processed by Python scripts.
- Boundary markers: None present in the data processing scripts to distinguish data from instructions.
- Capability inventory: Command execution via
subprocess.runis available inreplay_dlq.py. - Sanitization: The scripts use standard JSON deserialization and do not pass content directly into a large language model's instruction context, which mitigates the risk of the agent accidentally following instructions embedded within the JSON data.
Audit Metadata