engineering-codebase-onboarding-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill is purely instructional and does not involve executable code, remote dependencies, or privileged operations.
  • [PROMPT_INJECTION]: The instructions focus on establishing a methodical, evidence-first persona for the agent. There are no attempts to override safety guardrails or bypass system instructions.
  • [DATA_EXFILTRATION]: The skill instructions specifically mandate a read-only scope, prohibiting file modifications or network operations. No patterns for credential harvesting or data exfiltration were found.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest and analyze external codebase data, the risk of indirect prompt injection is mitigated by instructions that limit the agent to stating facts grounded in code and following a strict, descriptive output format without executive functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:36 AM
Security Audit — agent-trust-hub — engineering-codebase-onboarding-engineer