create-onboarding-guide

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill features an indirect prompt injection surface as it processes untrusted project data, but this is consistent with its intended use case and primary function. 1. Ingestion points: .chalk/docs/ directory and various project root configuration files. 2. Boundary markers: No explicit delimiters are used to isolate external content. 3. Capability inventory: Read, Glob, Grep, Bash, and Write tools. 4. Sanitization: No specific content validation or sanitization is performed on ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 08:10 AM