smb-onboard

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes platform-specific 'recipes' (e.g., cash-flow-snapshot, crm-maintenance, business-pulse) to demonstrate value to the user. These appear to be predefined internal functions used to process data from connected tools like 1C or CRM systems.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive business data (financials via 1C, client info via CRM, emails via Yandex 360), it does so within the expected scope of an onboarding assistant. There is no evidence of data being transmitted to unauthorized external domains; data is stored locally in the session memory block labeled '## Контекст бизнеса'.
  • [PROMPT_INJECTION]: The skill handles user input during an interview process to build a business profile. While this introduces a surface for indirect prompt injection (Category 8), the risk is low as the data is used primarily for documentation and context-setting within the platform's memory, and the skill includes explicit 'approval gates' requiring user confirmation before saving information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 06:56 PM
Security Audit — agent-trust-hub — smb-onboard