write-workflow-as-code

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes official platform libraries and tools, specifically the windmill-client Node.js package and the wmill Python package. These resources are provided by the author, Windmill Labs, for their intended infrastructure.
  • [COMMAND_EXECUTION]: The skill defines patterns for using the wmill CLI to preview, run, and deploy scripts. These commands are integral to the stated purpose of the skill as a developer tool and are configured to execute based on explicit user intent.
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized data exfiltration. Network operations facilitated by the wmill CLI (such as sync push) are directed toward the user's own Windmill workspace for deployment purposes.
  • [SAFE]: The skill includes best-practice recommendations for managing dependencies and resolving metadata, instructing the agent to notify users of any version changes detected during local configuration updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 08:37 AM
Security Audit — agent-trust-hub — write-workflow-as-code