startup-validator

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on extensive web research, fetching full articles from external sources to validate business ideas. This creates a surface where malicious instructions hidden in web pages could potentially influence the agent's subsequent analysis or actions.
  • Ingestion points: External data enters the agent context through web_search and web_fetch calls described in SKILL.md (Section 3).
  • Boundary markers: The instructions do not define clear delimiters (like XML tags) or safety warnings to distinguish untrusted web content from the skill's core instructions.
  • Capability inventory: The skill has access to web search, web fetching, and shell execution for its bundled Python script.
  • Sanitization: There is no mention of filtering or sanitizing the content retrieved from external URLs before processing.
  • [COMMAND_EXECUTION]: The skill utilizes a bundled Python script (scripts/market_analyzer.py) to calculate market metrics. The agent is instructed to write a JSON file and execute this script via the shell. While the script itself is local to the skill, it operates on data derived from potentially untrusted external web sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — startup-validator