ai-workflow-automation
Fail
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION] (HIGH): The skill handles a significant indirect prompt injection surface based on its architectural role.\n- Ingestion points: Processes external AI-generated content (Jasper, Claude, GPT) and parses untrusted workflow configuration files (YAML, JSON, PY, etc.).\n- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined in the instructions for processing external data.\n- Capability inventory: Manages high-impact actions including multi-channel distribution and integration with third-party automation platforms (Zapier, Make, n8n).\n- Sanitization: No input sanitization or validation logic is implemented for the content being processed beyond the provided diagnostic rules.\n- [NO_CODE] (SAFE): No executable scripts or binary files were found; the skill is composed entirely of Markdown documentation and YAML-based validation patterns.\n- [INFO] (LOW): Several reference files are either empty (references/sharp_edges.md) or missing from the package (references/patterns.md), which may lead to incomplete reasoning or failure to detect edge cases despite the skill's stated complexity.
Recommendations
- AI detected serious security threats
Audit Metadata