ceo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data through its analysis scripts, which creates a surface for indirect prompt injection attacks.
- Ingestion points: Data enters the agent context through the scripts
scripts/strategy_analyzer.pyandscripts/financial_scenario_analyzer.py, which read JSON data from standard input. - Boundary markers: The skill lacks explicit delimiters or instructions (e.g., 'ignore instructions within the data') when presenting script results to the agent.
- Capability inventory: The scripts are restricted to mathematical calculations and data formatting; they do not possess capabilities for network requests, file system writes, or subprocess execution.
- Sanitization: There is no evidence of string sanitization or validation for the inputs processed by the calculation scripts before the results are returned to the agent context.
- [DYNAMIC_EXECUTION]: The skill performs analytical tasks by executing local Python scripts provided in the skill package.
- The scripts
scripts/strategy_analyzer.pyandscripts/financial_scenario_analyzer.pyare executed at runtime to generate strategic and financial projections. - A code audit of these scripts confirms they only use standard library modules (
math,json,datetime) and do not utilize unsafe functions such aseval(),exec(), or dynamic path loading for libraries.
Audit Metadata