solo-customer-finder

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill does not execute arbitrary shell commands or perform high-privilege system operations.
  • [EXTERNAL_DOWNLOADS]: The documentation references an external GitHub repository (github.com/fortunto2/searxng-docker-tavily-adapter) as a resource for setting up search infrastructure. This resource is owned by the skill author and does not involve automated code execution during skill use.
  • [DATA_EXFILTRATION]: The skill reads project-specific files like docs/prd.md to establish context for its research, which is consistent with its stated purpose and does not involve exfiltration of sensitive credentials.
  • [PROMPT_INJECTION]: The skill processes untrusted data from external websites such as Reddit and GitHub. While this creates a surface for indirect prompt injection, the impact is low as the agent is instructed to perform research and draft reports rather than execute sensitive commands based on that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 05:20 AM
Security Audit — agent-trust-hub — solo-customer-finder