web-workspace-onboarding

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from project-native files like AGENTS.md and CLAUDE.md, which can be used to influence the agent's behavior via external content. • Ingestion points: Workspace instruction files (AGENTS.md, CLAUDE.md) and project-native repository profiles. • Boundary markers: The skill employs a 'Workspace Map' and 'Fact Ledger' to categorize and track the status of discovered information. • Capability inventory: Includes the execution of project-defined validation commands, file writing, and routing tasks to other project-native skills. • Sanitization: No specific filtering or sanitization of content within the workspace instruction files is mentioned.
  • [COMMAND_EXECUTION]: The skill directs the agent to identify and run 'validation commands' specified in the workspace contract. If these configuration files are malicious, this could lead to the execution of unauthorized shell commands in the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 10:26 PM
Security Audit — agent-trust-hub — web-workspace-onboarding