investor-materials

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: This skill is entirely instructional, providing a framework for creating pitch decks and financial models. It contains no Python scripts, Node.js code, or shell execution patterns.
  • [SAFE]: No obfuscation, prompt injection, credential exposure, or persistence mechanisms were detected in the skill content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided business metrics, bios, and financial assumptions to generate fundraising assets. While this represents a data ingestion surface, the skill does not possess any dangerous capabilities (such as network access, file system writing, or code execution) that could be leveraged if malicious content were embedded in that data.
  • Ingestion points: User-provided facts, metrics, and business data used to populate documents (SKILL.md).
  • Boundary markers: None explicitly defined within the instructions.
  • Capability inventory: None; the skill does not use any tools or scripts.
  • Sanitization: None specified for external data inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — investor-materials