write-script-rlang

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands using the wmill CLI, such as wmill script preview and wmill sync push, which are intended tools for interacting with the Windmill platform.
  • [DATA_EXFILTRATION]: The instructions demonstrate how to retrieve sensitive information like API keys and database configurations from the platform's secure variable and resource store using built-in R helper functions.
  • [REMOTE_CODE_EXECUTION]: The agent is instructed to execute the R code it generates locally using the wmill script preview command to validate script behavior and verify functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 08:37 AM
Security Audit — agent-trust-hub — write-script-rlang