paul-graham-perspective
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the web via search tools to perform analysis, creating a vulnerability to malicious instructions embedded in web content.\n
- Ingestion points: The 'PG-style research' step in
SKILL.mduses theWebSearchtool to gather data on founders, products, and market trends based on user queries.\n - Boundary markers: The skill includes an internal step to organize fact summaries before generating final output, which provides a conceptual buffer between raw data and persona response.\n
- Capability inventory: The skill possesses the capability to query the web and process the results into natural language responses.\n
- Sanitization: No specific technical sanitization or adversarial instruction filtering is defined for the content retrieved from external sources.\n- [PROMPT_INJECTION]: The skill includes instructions aimed at maintaining persona immersion that override default agent behavior regarding safety disclaimers.\n
- Evidence: The
角色扮演规则section inSKILL.mdexplicitly directs the agent to only state a disclaimer once upon activation and to suppress it in all subsequent turns to ensure character consistency.
Audit Metadata