w-onboard
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional text for repository onboarding. It does not contain any executable scripts, network requests, or sensitive file access.
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read internal repository files (e.g.,
AGENTS.md,mobile README). While this is a surface for indirect instructions, the skill does not grant the agent any autonomous dangerous capabilities that could be exploited via these files. - [COMMAND_EXECUTION]: The skill mentions standard project commands (
pnpm setup,pnpm dev). These are typical for local development environments and are documented as part of the repository's setup process.
Audit Metadata