migrating-workflow-v4-to-v5

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill analyzes local project files, such as package.json and source code, to identify migration requirements. This behavior introduces a surface where adversarial content within those files could potentially influence the agent's logic. This is a common consideration for agents that process external data. Ingestion points include project files read via grep, while capabilities include file modification and dependency installation.
  • [External Skill Reference]: The instructions direct the agent to fetch an additional skill from the author's official GitHub repository to handle specialized migration tasks. This reference targets a well-known organization and is part of the tool's modular design.
  • [Code Modification Instructions]: The skill contains logic for updating dependencies and performing mechanical code rewrites. These operations are the primary purpose of the skill, intended to automate the upgrade process between SDK versions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:10 AM
Security Audit — agent-trust-hub — migrating-workflow-v4-to-v5