workflow-router

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the repository which can contain malicious instructions.
  • Ingestion points: The skill directs the agent to inspect several files in the repository, including README, CONTRIBUTING, AI_ENGINEERING_WORKFLOW.md, AGENTS.md, and CLAUDE.md (SKILL.md).
  • Boundary markers: The skill does not define clear boundary markers or instructions to disregard embedded commands when reading these repository files.
  • Capability inventory: Based on the information gathered from the repository, the skill has the capability to propose file modifications and execute setup commands (SKILL.md).
  • Sanitization: There is no evidence of content sanitization or validation performed on the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 05:53 AM
Security Audit — agent-trust-hub — workflow-router