start
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes content from project configuration files and documentation (e.g.,
project.yaml,.claude/docs/*.md). This data ingestion creates a surface where malicious instructions embedded in these files could theoretically override or influence the onboarding logic. - Ingestion points: Local project files including
project.yaml,.claude/docs/technical-preferences.md,.claude/docs/code-root-resolution.md, and various design documents. - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded prompts when ingesting these file contents.
- Capability inventory: The skill is restricted to file management tools (
Read,Glob,Grep,Write,Edit) and user interaction (AskUserQuestion). It does not have access to shell execution or network operations. - Sanitization: No specific validation or sanitization is applied to the data read from project files before it is used to branch logic or recommend settings.
- [SAFE]: The skill performs legitimate project setup operations, such as creating and updating configuration files (
project.yaml,production/stage.txt) based on user preferences and detected project state. - [SAFE]: The requested toolset is appropriately scoped for the skill's primary purpose of project onboarding and does not include high-risk capabilities like arbitrary command execution.
Audit Metadata