paul-graham-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the web via search tools to perform analysis, creating a vulnerability to malicious instructions embedded in web content.\n
  • Ingestion points: The 'PG-style research' step in SKILL.md uses the WebSearch tool to gather data on founders, products, and market trends based on user queries.\n
  • Boundary markers: The skill includes an internal step to organize fact summaries before generating final output, which provides a conceptual buffer between raw data and persona response.\n
  • Capability inventory: The skill possesses the capability to query the web and process the results into natural language responses.\n
  • Sanitization: No specific technical sanitization or adversarial instruction filtering is defined for the content retrieved from external sources.\n- [PROMPT_INJECTION]: The skill includes instructions aimed at maintaining persona immersion that override default agent behavior regarding safety disclaimers.\n
  • Evidence: The 角色扮演规则 section in SKILL.md explicitly directs the agent to only state a disclaimer once upon activation and to suppress it in all subsequent turns to ensure character consistency.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — paul-graham-perspective