approval-workflow-generator

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • Category 4: Remote Code Execution (SAFE): No executable code, scripts, or remote dependencies were found. The skill consists entirely of markdown metadata and instructions.
  • Category 8: Indirect Prompt Injection (LOW): The skill defines a surface for processing untrusted user data to generate business workflows. Ingestion points: User input triggers the logic via phrases like 'approval workflow generator'. Boundary markers: Absent; the instructions do not include delimiters or warnings to ignore instructions within the user-provided data. Capability inventory: The skill is permitted to use Bash, Read, Write, and Edit tools across all potential operations. Sanitization: No explicit validation or sanitization logic is described for the content being processed or generated.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:48 PM