c-level-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection due to its reliance on shared context files.
- Ingestion points: The agents are designed to read
company-context.mdas a primary source of information for all strategic queries. - Boundary markers: The instructions do not define specific delimiters or guidelines to distinguish data from potentially malicious instructions within the
company-context.mdfile. - Capability inventory: The skill suite includes 25 Python tools (stdlib-only) and the ability to write structured markdown files to the project root.
- Sanitization: No validation or sanitization logic is specified for the input collected during the
/cs:setuponboarding questionnaire before it is written to disk and subsequently read by the agents.
Audit Metadata