ceo-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data through its analysis scripts, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: Data enters the agent context through the scripts scripts/strategy_analyzer.py and scripts/financial_scenario_analyzer.py, which read JSON data from standard input.
  • Boundary markers: The skill lacks explicit delimiters or instructions (e.g., 'ignore instructions within the data') when presenting script results to the agent.
  • Capability inventory: The scripts are restricted to mathematical calculations and data formatting; they do not possess capabilities for network requests, file system writes, or subprocess execution.
  • Sanitization: There is no evidence of string sanitization or validation for the inputs processed by the calculation scripts before the results are returned to the agent context.
  • [DYNAMIC_EXECUTION]: The skill performs analytical tasks by executing local Python scripts provided in the skill package.
  • The scripts scripts/strategy_analyzer.py and scripts/financial_scenario_analyzer.py are executed at runtime to generate strategic and financial projections.
  • A code audit of these scripts confirms they only use standard library modules (math, json, datetime) and do not utilize unsafe functions such as eval(), exec(), or dynamic path loading for libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — ceo-advisor