brand-discovery
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-supplied brand information stored in local Markdown files across multiple sessions to maintain interview continuity.
- Ingestion points: Reads module files (e.g.,
modules/10_purpose-why.md) andstate.jsonfrom the localbrand-identitydirectory in theSKILL.mdstart protocol. - Boundary markers: The module files use Markdown headers (
## Raw) to separate user input, but there are no explicit instructions for the agent to ignore potentially malicious commands that might be embedded in the user's past verbatim responses. - Capability inventory: The skill performs local file writes to
state.json,modules/*.md, andfounders/*.mdto record interview progress. - Sanitization: The skill implements strong validation for participant names (alphanumeric and hyphens only), module filenames (fixed sequence 10-90), and output paths (absolute paths only, rejecting
..segments) in theMulti-founder modesection ofSKILL.md.
Audit Metadata