onboarding

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill implements strict constraints to prevent the exposure of sensitive information. It is explicitly instructed not to include passwords, API keys, or secrets in the generated documentation, and to reference template files like .env.example instead of active environment files.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data which constitutes a potential surface for indirect prompt injection.
  • Ingestion points: Phase 1 performs comprehensive codebase analysis, reading project configuration and source files.
  • Boundary markers: The skill does not use specific delimiters to isolate analyzed codebase content in the generation prompt.
  • Capability inventory: The skill has file-read and file-write capabilities for documentation and telemetry logs.
  • Sanitization: Includes 'Do Not' safety constraints to ensure accuracy and prevent secret exposure, though no explicit string escaping is mentioned.- [COMMAND_EXECUTION]: While the skill extracts build, run, and test commands from the project configuration, it does so for documentation purposes only. It does not execute these commands during the onboarding guide generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — onboarding