workflow-setup

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Zero platform CLI to create, edit, and list workflows and triggers.\n- [EXTERNAL_DOWNLOADS]: The skill downloads the @vm0/cli package from the NPM registry. This is a vendor-owned resource associated with the author vm0-ai.\n- [SAFE]: The skill identifies ingestion points for untrusted data from Gmail, GitHub, and Google Calendar, which could potentially be used for indirect prompt injection. However, the instructions mitigate this risk by requiring explicit user confirmation before enabling sensitive automations or side effects.\n
  • Ingestion points: Gmail messages, GitHub labels, Google Calendar events, and Webhooks.\n
  • Boundary markers: None explicitly defined in the CLI instructions.\n
  • Capability inventory: Shell execution of workflow management commands.\n
  • Sanitization: Relies on the agent to summarize input into instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 10:14 PM
Security Audit — agent-trust-hub — workflow-setup