client-onboarding
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest data from external web sources such as search results, LinkedIn profiles, and ad scrapers.
- Ingestion points: Web fetch and scraping tools utilized in Phase 1 (SKILL.md).
- Boundary markers: The instructions for synthesizing information in Phase 2 do not specify the use of delimiters for untrusted data or include directions to ignore embedded instructions.
- Capability inventory: The skill writes research findings to the local filesystem and generates structured YAML blocks in HTML comments to guide downstream automation tools.
- Sanitization: There is no documentation of explicit sanitization or validation of the content retrieved from external sources.
- Assessment: Although an indirect prompt injection surface exists, it is consistent with the skill's intended use-case as an intelligence-gathering tool.
- [SAFE]: No hardcoded credentials, unauthorized network exfiltration, or malicious persistence mechanisms were detected.
- [SAFE]: The installation base command and the orchestration of other internal skills follow standard vendor patterns for the gooseworks-ai ecosystem.
Audit Metadata