onboarding-cro

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and provides business logic for user onboarding audits. No malicious patterns, command execution, or network exfiltration were detected across any of the files.\n- [PROMPT_INJECTION]: The skill defines a potential surface for indirect prompt injection as it requests reading a local context file (.claude/product-marketing-context.md in SKILL.md). Mandatory evidence: (1) Ingestion point is the specified markdown context file; (2) Boundary markers are not used in the prompt; (3) Capability inventory reveals no dangerous operations such as subprocess calls, file writing, or network access; (4) No sanitization is mentioned. Due to the lack of exploitable capabilities, the security risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — onboarding-cro