launch-day-conductor
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external platforms and user-pasted telemetry, which presents a surface for indirect prompt injection.\n
- Ingestion points: Data is pulled from Hacker News, Product Hunt, App Store, and GDELT via internal connector scripts, as well as user-provided metrics and community threads.\n
- Boundary markers: The instructions explicitly direct the agent to treat telemetry and threads as untrusted input and to ignore any instructions embedded within them.\n
- Capability inventory: The skill is capable of writing to local state files in the
memory/directory and executing authorized proposal requests throughregistry-events.py.\n - Sanitization: The agent is instructed to label all data by source type and is prohibited from treating external data as binary verdicts.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes connector scripts to fetch data from well-known services including Product Hunt, Hacker News (via Algolia), the App Store, and the GDELT Project. These operations are restricted to data retrieval from established services.
Audit Metadata