investor-matching

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious code, persistence mechanisms, or unauthorized privilege escalations were detected. The skill operates within its defined scope of research and document generation. Mentions of the vendor's own chimeranext-api-consumer agent represent expected integrated functionality.
  • [EXTERNAL_DOWNLOADS]: The skill references professional financial data services including Crunchbase, PitchBook, NVCA, and LAVCA. These are well-known, legitimate industry resources for venture capital research and do not represent a security risk.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests startup profiles and manual investor descriptions to generate reports. This is mitigated by the skill's narrow output scope (markdown documentation) and lack of executable capabilities. Ingestion points: startup-profile.md and manual investor input fields. Boundary markers: None. Capability inventory: Writes markdown research reports to local project directories. Sanitization: Not explicitly implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM