onboarding-cro

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily focused on providing business advice and frameworks for user activation and retention. It does not contain any executable code or malicious instructions.
  • [COMMAND_EXECUTION]: The skill mentions an 'ExecutionProxy Interface' (using a 'rtk' prefix) as a protocol for running terminal commands like 'npm test'. These are presented as best-practice examples for deterministic execution and do not constitute an attack vector.
  • [DATA_EXPOSURE]: No sensitive file paths or credentials were found. The skill references internal organizational documentation paths (e.g., 'docs/departments/Knowledge/'), which are consistent with the vendor's framework structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest product-specific context and user data. While it lacks explicit sanitization instructions, its primary function is advisory and its defined capabilities (MemoryStore, ExecutionProxy) are governed by platform-level 'Least Privilege' protocols described in the skill metadata, minimizing injection risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:35 AM
Security Audit — agent-trust-hub — onboarding-cro