codebase-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from a project's codebase (e.g., source code, manifests, and documentation) to generate onboarding artifacts. This creates a potential surface where malicious content embedded in codebase files could attempt to manipulate the agent's analysis or generated output.
- Ingestion points: Project configuration files (package.json, pyproject.toml, pom.xml, etc.) and source files analyzed during Phase 1 (Reconnaissance) and Phase 2 (Architecture Mapping) in SKILL.md.
- Boundary markers: The instructions do not specify the use of clear delimiters or instructions for the agent to ignore embedded commands when processing files from the repository.
- Capability inventory: The skill utilizes file discovery tools (glob/grep) and has file-writing capabilities specifically for creating or updating a
CLAUDE.mdfile. - Sanitization: No explicit sanitization, validation, or escaping of the ingested code content is described before the information is interpolated into the final onboarding guide.
Audit Metadata