acomo

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes workflow models and process data retrieved through the acomo CLI. Since these outputs come from an external platform, they represent an attack surface for indirect prompt injection where malicious workflow definitions or data could influence the agent's behavior. The skill is capability-rich, allowing for process submission and approval, which increases the potential impact of such an injection. There are no explicit sanitization or validation steps described for handling the CLI outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:44 AM
Security Audit — agent-trust-hub — acomo