onboard
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!command syntax to execute a local shell script (yaml-helper.sh) during the loading process. This is used to retrieve project-specific automation settings. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data including source code, documentation, and git logs to generate reports.
- Ingestion points: Phase 1 and 2 read project overview files, agent definitions, and repository history.
- Boundary markers: While it checks for data presence, it does not use specific delimiters to protect the agent from instructions embedded in the scanned files.
- Capability inventory: The skill can read, glob, grep, write files, and execute specific bash commands.
- Sanitization: There is no evidence of filtering or escaping content read from the project files before it is processed by the model.
- [COMMAND_EXECUTION]: The skill utilizes a restricted
Bashtool to run a project-local configuration helper.
Audit Metadata