cold-start-interview
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) by ingesting user responses and writing them to configuration files used by other accounting modules.\n
- Ingestion points: User responses provided during the multi-part interview in SKILL.md.\n
- Boundary markers: No specific delimiters or safety instructions are used when interpolating user strings into the firm-profile.md template.\n
- Capability inventory: The skill possesses file-write capabilities (~/.claude/plugins/config/) and executes tool calls for integration verification.\n
- Sanitization: The skill instructions do not specify any validation or sanitization for the ingested user content.\n- [COMMAND_EXECUTION]: The skill uses the --check-integrations flag to execute live tool calls to verify external connectors, which is consistent with its configuration purpose.
Audit Metadata