grandslam-offer

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill has a hard dependency on the growth-arsenal-workspace skill and a quality dependency on business-copy-style. It provides instructions for the user to install these dependencies from the author's repository using the npx skills add George-RD/growth-arsenal command.
  • [COMMAND_EXECUTION]: The skill executes various shell commands to interact with its workspace manager. This includes invoking python3 to run logic from the companion skill (arsenal.py) and using the open command to display generated HTML reports to the user.
  • [DYNAMIC_EXECUTION]: The skill invokes a Python script (arsenal.py) located within a dynamically resolved path (<workspace-skill-dir>). This script is responsible for state transitions, gating logic, and rendering views, representing dynamic loading and execution from computed paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from web research results, such as customer quotes, forum discussions, and competitor pricing, which is then passed to parallel sub-agents for adversarial review.
  • Ingestion points: The skill reads web research data and user-provided market interviews into the {project-name}-research.md file (Phase 0/1).
  • Boundary markers: The instructions specify structured JSON payloads for data exchange and stable issue_key identifiers for review normalization, helping to separate data from instructions.
  • Capability inventory: The skill has permissions to write files to the project directory, execute subprocesses via Python, and spawn sub-agents for specialized tasks.
  • Sanitization: The agent implements a normalization pass that requires consensus from multiple independent reviewers (e.g., same causal issue flagged by 2+ agents) before a finding is considered critical.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:12 PM
Security Audit — agent-trust-hub — grandslam-offer