onboard-codebase

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes git log --oneline -10 to analyze the repository's commit history and extract team conventions. This is a standard, read-only command used for informational analysis.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from the repository's source code and documentation, which could potentially contain malicious instructions aimed at the agent.\n
  • Ingestion points: The agent reads manifest files (e.g., package.json, pyproject.toml), documentation (README.md, CONTRIBUTING.md), and source code files.\n
  • Boundary markers: No specific boundary markers or instructions are provided to the agent to ignore instructions embedded within the analyzed files.\n
  • Capability inventory: The skill is limited to reading local files and executing git log. It does not perform network operations or file writes.\n
  • Sanitization: There is no explicit sanitization or filtering of the content read from the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — onboard-codebase