workflow

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/workflow_run.py orchestrates development tasks by invoking other specialized Python scripts (e.g., keil_build.py, gcc_build.py, jlink_exec.py) using subprocess.run. These calls are constructed as lists of arguments, which prevents standard shell injection vulnerabilities. The invoked scripts are part of the local workspace environment and are accessed via relative paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the workspace environment.
  • Ingestion points: The skill performs recursive scans (rglob) for project files (e.g., *.uvprojx) and reads configuration values from .embeddedskills/config.json.
  • Boundary markers: No explicit delimiters or 'ignore' instructions are provided when interpolating workspace data into tool parameters.
  • Capability inventory: subprocess.run is used extensively in scripts/workflow_run.py to execute build, flash, and debug commands based on discovered data.
  • Sanitization: The skill does not validate or sanitize workspace-derived file paths or configuration values before using them as command-line arguments.
  • [DYNAMIC_EXECUTION]: The script scripts/workflow_plan.py uses __import__("time") to access timing functions. This is a benign use of dynamic importing for a standard library module.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:15 AM
Security Audit — agent-trust-hub — workflow