founder-fit
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the WebSearch tool to gather information on market demands, buyer personas, and the founder's public presence on platforms such as LinkedIn, Twitter, and GitHub. This is part of its core functionality to profile business requirements and founder authority.
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by processing untrusted data from web search results without utilizing explicit boundary markers or instructions to disregard embedded commands. Ingestion points: Untrusted data enters the agent context through WebSearch operations in 'Step 1' and 'Step 2' (SKILL.md). Boundary markers: None are present; the instructions do not require the use of delimiters or warnings to ignore instructions found within retrieved data. Capability inventory: The agent maintains the ability to perform further WebSearch queries. Sanitization: There is no explicit sanitization or validation of the content returned from external search results before it is used to generate the founder-business fit analysis.
Audit Metadata