inbound-opportunity-protocol
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to research and analyze untrusted external data sources, including GitHub profiles, company websites, public documentation, and source code repositories (Phases 1 and 2). This creates a vulnerability surface where an attacker could embed malicious instructions in their public profile, website, or repository metadata to influence the agent's behavior during the 'Verify' or 'Architecture Comparison' stages.\n
- Ingestion points: External websites (LinkedIn, Twitter, Crunchbase), GitHub user profiles, and remote code repositories (SKILL.md, Phase 1 and 2).\n
- Boundary markers: None identified in the protocol instructions.\n
- Capability inventory: Uses the GitHub CLI (
gh) for searching and performs file system writes to update tracking logs and create briefing artifacts (SKILL.md, Phase 1.1, 6.1, and Artifacts section).\n - Sanitization: No specific sanitization or filtering logic is mentioned for the external content before it is processed.\n- [COMMAND_EXECUTION]: The protocol utilizes the GitHub CLI (
gh api search/users,gh search repos owner:<org>) to perform identity verification and research on external entities (SKILL.md, Phase 1.1). While these are standard tools, they interact with external systems based on potentially untrusted input provided by the entity reaching out.
Audit Metadata