workflow-onboard
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The skill accesses
.env.localand.env.exampleto identify environment variables required for project setup. While.env.localis a sensitive file path, the skill includes a specific guardrail instructing the agent to extract variable names only and never their values. There are no network exfiltration patterns or tools used to send this data externally. - [COMMAND_EXECUTION]: The skill uses local shell commands to retrieve repository history and recent changes.
- Evidence: Step 3 executes
git log --oneline -15andgit diff HEAD~5 --statto provide context on recent work. - [INDIRECT_PROMPT_INJECTION]: The skill ingests various files from the codebase (READMEs, manifests, source code) which are considered untrusted data and could contain embedded instructions.
- Ingestion points: Processes content from
README.md,package.json, and source files across thesrc/directory. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading repository content.
- Capability inventory: The skill utilizes shell execution for
gitcommands and produces a summary for the user. - Sanitization: No explicit sanitization or filtering of file content is mentioned before the information is summarized.
Audit Metadata