onboarding-cro

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [SAFE]: Analysis of the skill instructions, evaluation criteria, and reference documentation found no evidence of malicious patterns, obfuscation, or unauthorized command execution.
  • [DATA_EXFILTRATION]: The skill specifies that the agent should read from .agents/product-marketing-context.md or .claude/product-marketing-context.md to gain product context. This behavior is localized to the agent's environment and is not associated with any network capabilities or credentials that would enable data exfiltration.
  • [PROMPT_INJECTION]: The skill utilizes data from external context files, creating a theoretical surface for indirect prompt injection.
  • Ingestion points: .agents/product-marketing-context.md and .claude/product-marketing-context.md (referenced in SKILL.md).
  • Boundary markers: None identified; the skill instructs the agent to read the files directly.
  • Capability inventory: The skill has no active capabilities, tools, or scripts (no file-writing, no network access, no subprocess execution).
  • Sanitization: None; the content is read and used directly to inform the agent's recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 11:48 PM
Security Audit — agent-trust-hub — onboarding-cro