offboard

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data by scanning the local project directory (Item 7) and reading files like the README or TODO lists (Item 14). This creates a surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: local project directory, codebase (README, TODOs, branches).
  • Boundary markers: Not present.
  • Capability inventory: Grep for secrets, scan code, check branches.
  • Sanitization: Not present.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses sensitive paths such as .env files, SSH keys, and database dumps. However, this behavior is explicitly for the purpose of identifying and deleting sensitive data as part of an offboarding security cleanup, representing a safe use of these capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:00 AM
Security Audit — agent-trust-hub — offboard