fundraising-email

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting local files and processing them using powerful system tools, creating a theoretical surface for data-driven instruction override.
  • Ingestion points: The skill explicitly reads 'docs/departments/Executive/founder-context.md' and may access 'package.json' or 'docs/graph.json' as part of its global protocols.
  • Boundary markers: The instructions do not specify the use of delimiters or explicit 'ignore' prompts for the content read from these files.
  • Capability inventory: The skill is configured with 'run_shell_command', 'write_file', 'replace', 'read_file', 'grep_search', and 'glob'.
  • Sanitization: The 'Security & Multi-Agent Hygiene' section mitigates risk by instructing the agent to treat external data as hostile and to redact sensitive information (PII/secrets) before further processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:35 AM
Security Audit — agent-trust-hub — fundraising-email