startup-idea-validator
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill gathers data from various untrusted external sources, such as Reddit, YouTube comments, and Amazon reviews, to generate validation reports and calculate project scores.
- Ingestion points: Data is retrieved from the live web using tools like
web_scrape,youtube_comments,amazon_reviews, andx_profile(SKILL.md). - Boundary markers: Although the skill instructs the agent to store research in a structured JSON format (
research.json), it lacks explicit delimiters to separate scraped text from instructions. - Capability inventory: The agent is instructed to execute a local Python script (
scripts/score_idea.py) and generate HTML artifacts based on the ingested data. - Sanitization: The instructions do not define any sanitization or filtering mechanisms for the scraped content before it is processed.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to configure the
scrapingdog-mcpserver usingnpx, which involves downloading code from the npm registry. ScrapingDog is a well-known service for web scraping APIs. - [COMMAND_EXECUTION]: The skill utilizes a local Python script,
scripts/score_idea.py, to parse research data and generate a deterministic validation score.
Audit Metadata