onboard

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill constructs shell commands by directly interpolating user input (such as names and roles) into command strings for execution via the Bash tool.
  • Evidence: In SKILL.md, Step 3 instructs the agent to run python onboard_manual.py "Full Name" "Role" "personal@email.com".
  • Risk: Maliciously crafted user input containing shell metacharacters (e.g., ;, &, or |) could lead to the execution of unintended commands on the host system.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by ingesting untrusted data that is then used in high-privilege operations.
  • Ingestion points: User data (Full Name, Role, Personal Email) is collected via the AskUserQuestion tool as described in SKILL.md.
  • Boundary markers: The skill does not use boundary markers or delimiters to isolate user-provided strings when constructing the shell command.
  • Capability inventory: The skill utilizes the Bash tool to execute local Python scripts that interact with Google Workspace and Slack.
  • Sanitization: There is no evidence of input validation, sanitization, or escaping of the user-provided strings before they are interpolated into the command line.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM