launch-tier-planner

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill incorporates defensive instructions to mitigate indirect prompt injection, explicitly directing the agent to treat all pasted plans, partner documents, and external exports as untrusted input and to disregard any instructions embedded within them.
  • [SAFE]: Data integrity is maintained by using a mediated 'proposal' system. Instead of modifying the core launch registry directly, the skill sends authorized requests to a local script (registry-events.py), which acts as a gateway for project records.
  • [SAFE]: External data access is scoped to specific, localized connector scripts (hn.py, gdelt.py) for public telemetry, preventing the agent from making arbitrary or unmonitored network requests.
  • [SAFE]: The skill follows a principle of least privilege by defining clear boundaries; it only sizes launches and registers risks, delegating more sensitive tasks like date selection or budget optimization to other specialized skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 07:29 PM
Security Audit — agent-trust-hub — launch-tier-planner