onboarding-cro

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and configuration. It does not contain any executable code, shell scripts, or binary files.
  • [DATA_EXPOSURE]: The instructions direct the agent to read specific context files such as .agents/product-marketing-context.md. This is a standard pattern for context-aware agents and is limited to non-sensitive project documentation.
  • [PROMPT_INJECTION]: While the skill ingests external data from project context files which could serve as an indirect prompt injection vector, the lack of dangerous capabilities such as file writing, network access, or command execution prevents the escalation of this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 07:41 PM
Security Audit — agent-trust-hub — onboarding-cro