onboard

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! command syntax to execute a local shell script (yaml-helper.sh) during the loading process. This is used to retrieve project-specific automation settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data including source code, documentation, and git logs to generate reports.
  • Ingestion points: Phase 1 and 2 read project overview files, agent definitions, and repository history.
  • Boundary markers: While it checks for data presence, it does not use specific delimiters to protect the agent from instructions embedded in the scanned files.
  • Capability inventory: The skill can read, glob, grep, write files, and execute specific bash commands.
  • Sanitization: There is no evidence of filtering or escaping content read from the project files before it is processed by the model.
  • [COMMAND_EXECUTION]: The skill utilizes a restricted Bash tool to run a project-local configuration helper.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — onboard