git-pr-workflows-onboard
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill acts as a high-level instructional guide and template provider for employee onboarding.
- [DATA_EXPOSURE]: The skill mentions sensitive setup steps such as configuring SSH keys, AWS accounts, and API keys. However, these are listed as checklist items for the user or new hire to perform manually. The instructions explicitly recommend using a secrets manager for credentials, which aligns with security best practices.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided arguments ($ARGUMENTS) to customize onboarding plans. While this is an entry point for external data, the skill's capabilities are limited to text generation and plan structuring, presenting no significant exploitation risk.
Audit Metadata