using-workflows
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [Prompt Injection] (LOW): Detected surface for Indirect Prompt Injection. Ingestion points: The
chatWorkflowfunction inSKILL.mdacceptsuserMessage. Boundary markers: None identified in the provided snippets. Capability inventory: The workflow performs database writes and executes AI agents. Sanitization: No input sanitization is present beyond type assertion.
Audit Metadata