codebase-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from a project's codebase (e.g., source code, manifests, and documentation) to generate onboarding artifacts. This creates a potential surface where malicious content embedded in codebase files could attempt to manipulate the agent's analysis or generated output.
  • Ingestion points: Project configuration files (package.json, pyproject.toml, pom.xml, etc.) and source files analyzed during Phase 1 (Reconnaissance) and Phase 2 (Architecture Mapping) in SKILL.md.
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions for the agent to ignore embedded commands when processing files from the repository.
  • Capability inventory: The skill utilizes file discovery tools (glob/grep) and has file-writing capabilities specifically for creating or updating a CLAUDE.md file.
  • Sanitization: No explicit sanitization, validation, or escaping of the ingested code content is described before the information is interpolated into the final onboarding guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — codebase-onboarding