venture-sensei
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the internet via
WebSearchandWebFetchtools (Step 1: Research). This data is then used to construct a startup critique (Step 2: Output). There are no delimiters or instructions to ignore embedded commands within the retrieved data, which could allow malicious web content to influence the agent's behavior. - Ingestion points:
SKILL.md(Step 1: Research) - Boundary markers: Absent for untrusted external data.
- Capability inventory: Tool access to
WebSearchandWebFetchfor data retrieval. - Sanitization: No sanitization or filtering of external input is performed.
- [EXTERNAL_DOWNLOADS]: The skill utilizes network-enabled tools to download and process content from external third-party domains during the business evaluation process. This is a core part of its intended functionality for competitor and market research.
Audit Metadata