onboard
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill collects user-provided information through a seven-question interview and persists it into files that define the agent's identity and operational context.
- Ingestion points: User responses provided during the intake process in Step 2 of
SKILL.md. - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands when writing user input to the final scaffolded files.
- Capability inventory: The skill performs multiple file-write operations to core configuration files, including
context/about-me.md,context/about-business.md,context/priorities.md,references/voice.md,connections.md, andCLAUDE.md. - Sanitization: No sanitization, escaping, or validation is performed on user input before interpolation. Voice samples are explicitly required to be pasted verbatim into
references/voice.md. - [COMMAND_EXECUTION]: The skill instructions suggest the execution of a local setup script (
python tools/graphify_setup.py install) and direct the user to manually install tools or write API scripts in theconnections.mdworkflow. While these are user-initiated setup steps, they involve shell command execution and environment modification.
Audit Metadata