startup-validator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates a comprehensive market research workflow that fetches content from various external web sources, creating a potential surface for indirect prompt injection. * Ingestion points: The skill performs at least 10 to 15 web searches to gather market projections, competitor data, and industry trends as described in the Core Workflow section of SKILL.md. * Boundary markers: There are no explicit instructions for the agent to use delimiters or specific ignore commands when processing the fetched content. * Capability inventory: The skill has access to network tools for research and local script execution for data analysis. * Sanitization: The instructions do not define a process for sanitizing or validating external content before it is processed by the agent.
- [DYNAMIC_EXECUTION]: The skill executes a bundled Python script to perform quantitative business calculations. * Evidence: SKILL.md contains instructions to execute scripts/market_analyzer.py using a JSON file as input. * Context: This execution is limited to a local script provided within the skill package, which is used for calculating market metrics like TAM/SAM/SOM and unit economics, representing the primary intended functionality.
Audit Metadata