acomo
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes workflow models and process data retrieved through the
acomoCLI. Since these outputs come from an external platform, they represent an attack surface for indirect prompt injection where malicious workflow definitions or data could influence the agent's behavior. The skill is capability-rich, allowing for process submission and approval, which increases the potential impact of such an injection. There are no explicit sanitization or validation steps described for handling the CLI outputs.
Audit Metadata