onboarding-cro
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily focused on providing business advice and frameworks for user activation and retention. It does not contain any executable code or malicious instructions.
- [COMMAND_EXECUTION]: The skill mentions an 'ExecutionProxy Interface' (using a 'rtk' prefix) as a protocol for running terminal commands like 'npm test'. These are presented as best-practice examples for deterministic execution and do not constitute an attack vector.
- [DATA_EXPOSURE]: No sensitive file paths or credentials were found. The skill references internal organizational documentation paths (e.g., 'docs/departments/Knowledge/'), which are consistent with the vendor's framework structure.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest product-specific context and user data. While it lacks explicit sanitization instructions, its primary function is advisory and its defined capabilities (MemoryStore, ExecutionProxy) are governed by platform-level 'Least Privilege' protocols described in the skill metadata, minimizing injection risk.
Audit Metadata