user-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from USER.md and MEMORY.md to establish context. This data, sourced from prior user interactions, presents a surface for indirect prompt injection.
  • Ingestion points: Context and memory are read from USER.md and MEMORY.md files during the initial step of onboarding.
  • Boundary markers: No specific delimiters or instruction-ignoring markers are defined to isolate historical memory from current task instructions.
  • Capability inventory: The skill utilizes tools including wechat, telegram_bot, scheduled_task, and memory to perform actions and persist data.
  • Sanitization: The skill does not implement explicit validation or sanitization rules for the ingested historical data.
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration files, with no executable code or scripts provided.
  • [SAFE]: The skill follows security best practices by requiring the agent to present samples of automated output for user approval before registering any recurring jobs via the scheduled_task tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:32 PM
Security Audit — agent-trust-hub — user-onboarding