launch-day-conductor

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external platforms and user-pasted telemetry, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Data is pulled from Hacker News, Product Hunt, App Store, and GDELT via internal connector scripts, as well as user-provided metrics and community threads.\n
  • Boundary markers: The instructions explicitly direct the agent to treat telemetry and threads as untrusted input and to ignore any instructions embedded within them.\n
  • Capability inventory: The skill is capable of writing to local state files in the memory/ directory and executing authorized proposal requests through registry-events.py.\n
  • Sanitization: The agent is instructed to label all data by source type and is prohibited from treating external data as binary verdicts.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes connector scripts to fetch data from well-known services including Product Hunt, Hacker News (via Algolia), the App Store, and the GDELT Project. These operations are restricted to data retrieval from established services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:29 PM
Security Audit — agent-trust-hub — launch-day-conductor