windsurf-cascade-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation and configuration templates. There are no executable scripts, binary files, or automated command executions contained within the provided files.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to generate instructions ('.windsurfrules') for another AI agent (Cascade). While this involves creating prompt content, it is the intended administrative function of the skill and does not include patterns meant to subvert the primary agent's safety or instructions.
  • Ingestion points: Project architecture and convention documentation described in 'references/directory-structure.md'.
  • Boundary markers: None explicitly defined in the provided templates.
  • Capability inventory: The skill manifest allows 'Write', 'Edit', and 'Bash', though no specific bash commands are implemented in the scripts.
  • Sanitization: Not applicable as the skill provides static templates for manual or guided completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:49 AM
Security Audit — agent-trust-hub — windsurf-cascade-onboarding