project-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of analyzing untrusted codebase files.
- Ingestion points: The skill reads project configuration files such as
package.json,Makefile, andpyproject.toml, as well as general project source files viaRead,Glob, andGrep(SKILL.md). - Boundary markers: No specific boundary markers or instructions to ignore embedded instructions are used when interpolating file contents into the agent's context.
- Capability inventory: The skill utilizes
Read,Glob,Grep,Bash, andWritetools to analyze and interact with the environment. - Sanitization: Verification of discovered commands relies on the agent's judgment and the manual inclusion of flags like
--version, but no programmatic sanitization of extracted data is performed before it reaches theBashtool. - [COMMAND_EXECUTION]: The skill guides the agent to execute shell commands discovered within the project environment (e.g.,
npm run --silent). While the instructions recommend using safe flags and require user permission for substantial work, this involves executing logic derived directly from untrusted project metadata.
Audit Metadata