workflow-onboard

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The skill accesses .env.local and .env.example to identify environment variables required for project setup. While .env.local is a sensitive file path, the skill includes a specific guardrail instructing the agent to extract variable names only and never their values. There are no network exfiltration patterns or tools used to send this data externally.
  • [COMMAND_EXECUTION]: The skill uses local shell commands to retrieve repository history and recent changes.
  • Evidence: Step 3 executes git log --oneline -15 and git diff HEAD~5 --stat to provide context on recent work.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests various files from the codebase (READMEs, manifests, source code) which are considered untrusted data and could contain embedded instructions.
  • Ingestion points: Processes content from README.md, package.json, and source files across the src/ directory.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading repository content.
  • Capability inventory: The skill utilizes shell execution for git commands and produces a summary for the user.
  • Sanitization: No explicit sanitization or filtering of file content is mentioned before the information is summarized.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — workflow-onboard