ceo-personal-os
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown files and documentation templates. There are no Python, Node.js, or shell scripts included in the package.- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process documents from an
uploads/directory to summarize patterns and update amemory.mdfile. While this is a data ingestion surface, the risk is mitigated by the lack of high-privilege tools. * Ingestion points: User-provided files in theuploads/directory. * Boundary markers: Not specified in the instructions. * Capability inventory: Limited to file reading and writing within the skill directory; no network or shell capabilities are present. * Sanitization: No explicit sanitization or filtering logic is defined for the uploaded content.- [SAFE]: All external URL references are for attribution purposes and target well-known services (e.g., x.com). These links do not involve automated downloads or remote code execution.
Audit Metadata