onboarding
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data access were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential ingestion surface for untrusted data.
- Ingestion points: The instructions in SKILL.md prompt the agent to read
.agents/marketing-context.mdif it exists in the project context. - Boundary markers: Absent; there are no specific instructions or delimiters provided to ignore potentially malicious directives within the context file.
- Capability inventory: The skill is restricted to generating text-based design and optimization deliverables (journey maps, event contracts). It lacks access to any tools for code execution, file system modification, or network operations.
- Sanitization: Absent; the external marketing context is processed directly to inform the onboarding design analysis.
Audit Metadata