startup-analyst

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and metadata are consistent with its stated purpose as a startup business analyst. No suspicious commands, hidden content, or unauthorized network operations were found.\n- [PROMPT_INJECTION]: The skill incorporates an indirect prompt injection surface as it ingests untrusted data from web searches to produce analytical reports. However, this is consistent with its intended function.\n
  • Ingestion points: Web search results for market data, public company analysis, and competitive intelligence (SKILL.md).\n
  • Boundary markers: Absent; instructions do not explicitly mandate the use of delimiters for external content.\n
  • Capability inventory: Web search, file writing for analysis reports, and invocation of plugin commands (SKILL.md).\n
  • Sanitization: Not specified; instructions focus on accuracy and citation rather than content filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:22 AM
Security Audit — agent-trust-hub — startup-analyst