onboard
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill constructs shell commands by directly interpolating user input (such as names and roles) into command strings for execution via the Bash tool.
- Evidence: In
SKILL.md, Step 3 instructs the agent to runpython onboard_manual.py "Full Name" "Role" "personal@email.com". - Risk: Maliciously crafted user input containing shell metacharacters (e.g.,
;,&, or|) could lead to the execution of unintended commands on the host system. - [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by ingesting untrusted data that is then used in high-privilege operations.
- Ingestion points: User data (Full Name, Role, Personal Email) is collected via the
AskUserQuestiontool as described inSKILL.md. - Boundary markers: The skill does not use boundary markers or delimiters to isolate user-provided strings when constructing the shell command.
- Capability inventory: The skill utilizes the
Bashtool to execute local Python scripts that interact with Google Workspace and Slack. - Sanitization: There is no evidence of input validation, sanitization, or escaping of the user-provided strings before they are interpolated into the command line.
Audit Metadata