discovery
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection during its research phases. Ingestion points: Research includes Reddit, Hacker News, G2, and other public forums, as well as the user's public social profiles. Boundary markers: The instructions lack delimiters to isolate untrusted external content. Capability inventory: The skill has read/write access to the local filesystem and network access. Sanitization: No sanitization of external content is specified.
- [DATA_EXFILTRATION]: The skill aggregates sensitive data such as capital and personal runway, storing it in the ~/.alexandre-trotel-skills/ directory. This concentration of sensitive information represents an exposure risk if the agent's context is compromised.
Audit Metadata