project-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of analyzing untrusted codebase files.
  • Ingestion points: The skill reads project configuration files such as package.json, Makefile, and pyproject.toml, as well as general project source files via Read, Glob, and Grep (SKILL.md).
  • Boundary markers: No specific boundary markers or instructions to ignore embedded instructions are used when interpolating file contents into the agent's context.
  • Capability inventory: The skill utilizes Read, Glob, Grep, Bash, and Write tools to analyze and interact with the environment.
  • Sanitization: Verification of discovered commands relies on the agent's judgment and the manual inclusion of flags like --version, but no programmatic sanitization of extracted data is performed before it reaches the Bash tool.
  • [COMMAND_EXECUTION]: The skill guides the agent to execute shell commands discovered within the project environment (e.g., npm run --silent). While the instructions recommend using safe flags and require user permission for substantial work, this involves executing logic derived directly from untrusted project metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:28 AM
Security Audit — agent-trust-hub — project-onboarding