aep-onboard

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The onboarding instructions include a command to install the Bun runtime by fetching a shell script from its official domain (https://bun.sh/install) and piping it to bash. This is a recognized installation method for the Bun project.\n- [EXTERNAL_DOWNLOADS]: The skill automates the installation of development tools from well-known sources, including @anthropic-ai/claude-code, @openai/codex, and @fission-ai/openspec via NPM. It also utilizes the skills CLI from a trusted organization's repository to manage skill installation.\n- [COMMAND_EXECUTION]: The skill includes shell scripts for local environment diagnostics, checking the presence and versions of required tools like node, git, and jq. Additionally, it provides configuration templates for agent hooks that use jq to enforce project-specific concurrency rules.\n- [PROMPT_INJECTION]: The instruction templates contain guidelines that define the operational boundaries for AI agents, such as requiring autonomous work on reversible actions and following project conventions. These are designed to align agent behavior with engineering best practices rather than bypassing safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 11:02 AM
Security Audit — agent-trust-hub — aep-onboard