cw-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from writing samples provided by the user and existing workspace files to generate rules for writing guides.
- Ingestion points: The skill reads user-supplied representative samples and external files like
../../references/context-contract.mdandTASTE.mdto define voice and style rules. - Boundary markers: There are no explicit instructions to delimit user samples or to ignore embedded instructions within that content during the analysis phase.
- Capability inventory: The skill has the capability to write to
VOICE.mdandSTYLE.mdand can trigger thecw-setup-projectskill. - Sanitization: No mechanisms for sanitizing or escaping the content of user-provided samples are specified before they are processed and incorporated into the profile guides.
Audit Metadata