ceo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external, potentially untrusted data to provide executive guidance.
- Ingestion points: The skill explicitly instructs the agent to read 'company-context.md' and uses company data as input for the 'strategy_analyzer.py' and 'financial_scenario_analyzer.py' scripts.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when interpolating external company context into the agent's prompt.
- Capability inventory: The skill includes 'Proactive Triggers' that monitor company data and a 'Role Invocation' mechanism ([INVOKE:role|question]) which could be triggered or manipulated by malicious content within the ingested data.
- Sanitization: There are no specific instructions for the agent to sanitize, escape, or validate the external content before processing it or using it to trigger actions.
Audit Metadata