business-idea-finder

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It instructs the agent to fetch and analyze user-generated content from external social media platforms (Reddit, HackerNews, Twitter, etc.). Maliciously crafted posts on these platforms could contain instructions that attempt to hijack the agent's logic when it processes search results.\n
  • Ingestion points: Web search results from Reddit, HackerNews, Twitter/X, IndieHackers, Product Hunt, and Threads as specified in SKILL.md and references/platform-strategies.md.\n
  • Boundary markers: Absent. There are no specific instructions or delimiters provided to isolate the fetched external content from the agent's instruction set.\n
  • Capability inventory: The skill relies on the agent's core reasoning and web search capabilities to rank and validate ideas.\n
  • Sanitization: Absent. There are no instructions to sanitize or filter the content of the search results for potential injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 01:01 AM
Security Audit — agent-trust-hub — business-idea-finder