agentic-qa-onboard

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains behavioral instructions directing the agent to adopt a specific 'Teaching mode' register, using full sentences and simple language for user clarity. This is an instructional preference for interaction style rather than an attempt to bypass safety protocols.
  • [COMMAND_EXECUTION]: The skill defines a mechanism for the agent to launch the user's default browser to display HTML presentations using platform-specific commands like 'open', 'xdg-open', and 'start'. This is governed by a strict protocol requiring the agent to announce the action and obtain user consent before execution.
  • [EXTERNAL_DOWNLOADS]: The skill references a setup process ('bun run setup') that retrieves the engram component and several community skills from trusted organizations and the vendor's official GitHub Pages repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:14 PM
Security Audit — agent-trust-hub — agentic-qa-onboard