workflow-router
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the repository which can contain malicious instructions.
- Ingestion points: The skill directs the agent to inspect several files in the repository, including
README,CONTRIBUTING,AI_ENGINEERING_WORKFLOW.md,AGENTS.md, andCLAUDE.md(SKILL.md). - Boundary markers: The skill does not define clear boundary markers or instructions to disregard embedded commands when reading these repository files.
- Capability inventory: Based on the information gathered from the repository, the skill has the capability to propose file modifications and execute setup commands (
SKILL.md). - Sanitization: There is no evidence of content sanitization or validation performed on the ingested data.
Audit Metadata