skills/wildcard/caro/onboard/Gen Agent Trust Hub

onboard

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses rp-cli (RepoPrompt) and standard shell commands like ls and find to explore the codebase. These are legitimate tools for project analysis and are used within the local workspace context.\n- [DATA_EXFILTRATION]: No evidence of data exfiltration was found. The skill operates on local project files and does not perform network requests to external or untrusted domains.\n- [PROMPT_INJECTION]: The instructions do not contain patterns for bypassing safety filters, ignoring instructions, or extracting system prompts. The agent is directed to follow standard onboarding procedures.\n- [SAFE]: The skill processes untrusted project data (brownfield codebase), creating a surface for indirect prompt injection. Ingestion point: local project files via rp-cli. Boundary markers: absent. Capability inventory: local file exploration, shell commands, and file writes to thoughts/ledgers/. Sanitization: absent. The risk is considered safe as no high-privilege or external network capabilities are enabled.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 03:26 PM
Security Audit — agent-trust-hub — onboard