skills/alvindean/soniq/ceo-advisor/Gen Agent Trust Hub

ceo-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external, potentially untrusted data to provide executive guidance.
  • Ingestion points: The skill explicitly instructs the agent to read 'company-context.md' and uses company data as input for the 'strategy_analyzer.py' and 'financial_scenario_analyzer.py' scripts.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when interpolating external company context into the agent's prompt.
  • Capability inventory: The skill includes 'Proactive Triggers' that monitor company data and a 'Role Invocation' mechanism ([INVOKE:role|question]) which could be triggered or manipulated by malicious content within the ingested data.
  • Sanitization: There are no specific instructions for the agent to sanitize, escape, or validate the external content before processing it or using it to trigger actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM