w-onboard

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional text for repository onboarding. It does not contain any executable scripts, network requests, or sensitive file access.
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read internal repository files (e.g., AGENTS.md, mobile README). While this is a surface for indirect instructions, the skill does not grant the agent any autonomous dangerous capabilities that could be exploited via these files.
  • [COMMAND_EXECUTION]: The skill mentions standard project commands (pnpm setup, pnpm dev). These are typical for local development environments and are documented as part of the repository's setup process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:00 AM
Security Audit — agent-trust-hub — w-onboard