start

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes content from project configuration files and documentation (e.g., project.yaml, .claude/docs/*.md). This data ingestion creates a surface where malicious instructions embedded in these files could theoretically override or influence the onboarding logic.
  • Ingestion points: Local project files including project.yaml, .claude/docs/technical-preferences.md, .claude/docs/code-root-resolution.md, and various design documents.
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded prompts when ingesting these file contents.
  • Capability inventory: The skill is restricted to file management tools (Read, Glob, Grep, Write, Edit) and user interaction (AskUserQuestion). It does not have access to shell execution or network operations.
  • Sanitization: No specific validation or sanitization is applied to the data read from project files before it is used to branch logic or recommend settings.
  • [SAFE]: The skill performs legitimate project setup operations, such as creating and updating configuration files (project.yaml, production/stage.txt) based on user preferences and detected project state.
  • [SAFE]: The requested toolset is appropriately scoped for the skill's primary purpose of project onboarding and does not include high-risk capabilities like arbitrary command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — start