onboard-codebase
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
git log --oneline -10to analyze the repository's commit history and extract team conventions. This is a standard, read-only command used for informational analysis.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from the repository's source code and documentation, which could potentially contain malicious instructions aimed at the agent.\n - Ingestion points: The agent reads manifest files (e.g.,
package.json,pyproject.toml), documentation (README.md,CONTRIBUTING.md), and source code files.\n - Boundary markers: No specific boundary markers or instructions are provided to the agent to ignore instructions embedded within the analyzed files.\n
- Capability inventory: The skill is limited to reading local files and executing
git log. It does not perform network operations or file writes.\n - Sanitization: There is no explicit sanitization or filtering of the content read from the repository.
Audit Metadata