Codebase Onboarding Engineer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown instructions and does not include any executable scripts, binaries, or configuration files.
  • [SAFE]: No malicious patterns, obfuscation, credential harvesting, or unauthorized data exfiltration were detected. The skill instructions follow security best practices by enforcing a read-only policy and factual reporting.
  • [PROMPT_INJECTION]: The skill involves analyzing external repository content which creates a surface for indirect prompt injection. 1. Ingestion points: The agent reads source code, manifests, and config files from a user's repository. 2. Boundary markers: The instructions contain explicit rules to state only facts grounded in inspected code and to avoid inference or speculation. 3. Capability inventory: The skill is strictly read-only and prohibits file modification or state changes. 4. Sanitization: No explicit sanitization of code comments or content is performed. The risk is minimized by the agent's restricted scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:25 AM
Security Audit — agent-trust-hub — Codebase Onboarding Engineer