skills/ai-vita/skills/onboarding-cro/Gen Agent Trust Hub

onboarding-cro

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and evaluation logic. It contains no executable code, remote dependencies, or commands that interact with the system or network.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection through the ingestion of external context files.
  • Ingestion points: SKILL.md (Initial Assessment section) instructs the agent to read .agents/product-marketing-context.md or .claude/product-marketing-context.md before proceeding.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions within these files.
  • Capability inventory: None. The skill's scope is restricted to generating text-based recommendations and does not have access to tools for file modification, network communication, or shell execution.
  • Sanitization: Absent; the agent is not instructed to validate or sanitize the content of the ingested context files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 05:17 AM
Security Audit — agent-trust-hub — onboarding-cro