workflow
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/workflow_run.pyorchestrates development tasks by invoking other specialized Python scripts (e.g.,keil_build.py,gcc_build.py,jlink_exec.py) usingsubprocess.run. These calls are constructed as lists of arguments, which prevents standard shell injection vulnerabilities. The invoked scripts are part of the local workspace environment and are accessed via relative paths. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the workspace environment.
- Ingestion points: The skill performs recursive scans (
rglob) for project files (e.g.,*.uvprojx) and reads configuration values from.embeddedskills/config.json. - Boundary markers: No explicit delimiters or 'ignore' instructions are provided when interpolating workspace data into tool parameters.
- Capability inventory:
subprocess.runis used extensively inscripts/workflow_run.pyto execute build, flash, and debug commands based on discovered data. - Sanitization: The skill does not validate or sanitize workspace-derived file paths or configuration values before using them as command-line arguments.
- [DYNAMIC_EXECUTION]: The script
scripts/workflow_plan.pyuses__import__("time")to access timing functions. This is a benign use of dynamic importing for a standard library module.
Audit Metadata