vertical-onboarding
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill functions as a documentation playbook for product managers and architects to define onboarding milestones and data import processes.
- [COMMAND_EXECUTION]: The skill uses standard, limited file system tools (
Read,Write,Grep,Glob) which are restricted via thepathsconfiguration to specific documentation directories (docs/data-import/,docs/architecture/,docs/design/). This follows the principle of least privilege. - [DATA_EXFILTRATION]: There are no network-capable tools or commands (such as
curlorwget) present in the skill, and no evidence of credential harvesting or sensitive data access. - [PROMPT_INJECTION]: The instructions are clear and focused on the stated purpose of product design. No patterns involving behavior overrides, safety filter bypasses, or instructions to ignore previous rules were found.
Audit Metadata