thought-leadership

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to ingest and process external, potentially untrusted data sources to generate its content.
  • Ingestion points: The skill processes user-supplied "research", "firm experience", and "approved cases" as defined in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate or treat external data as untrusted, which could allow instructions hidden in research material to influence agent behavior.
  • Capability inventory: The skill contains only markdown instructions and no code files. It does not define any capabilities for network access, file system modifications, or subprocess execution.
  • Sanitization: The instructions do not specify any validation or sanitization steps for external data before processing.
  • [NO_CODE]: The skill consists entirely of instructional markdown files and contains no scripts, binaries, or executable code, which significantly limits the risk of traditional malware or malicious command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:46 PM
Security Audit — agent-trust-hub — thought-leadership