business-growth-skills

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download additional components from a remote GitHub repository (alirezarezvani/claude-skills) using the npx agent-skills-cli command.- [COMMAND_EXECUTION]: The skill's functionality relies on executing external Python scripts (e.g., health_score_calculator.py, pipeline_analyzer.py) that are not included in the provided package but are fetched from remote sources.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as RFPs, customer health records, and contract templates.
  • Ingestion points: Processes data from customer success metrics, RFP documents, and pipeline logs.
  • Boundary markers: There are no defined boundary markers or instructions provided to the agent to treat external data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill possesses the capability to execute shell commands via Python scripts.
  • Sanitization: No sanitization or validation mechanisms are described for the external data before it is processed by the scripts or the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 04:11 PM
Security Audit — agent-trust-hub — business-growth-skills