fundraising-narrative
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGNO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown text, structured templates, and illustrative examples. It does not include any Python or Node.js scripts, shell commands, or network-enabled tools.
- [INDIRECT_PROMPT_INJECTION]: The skill prompts require the ingestion of user-supplied data to generate narratives.
- Ingestion points: Company descriptions, metrics, and stage information provided by the user in the 'How to Use' section.
- Boundary markers: Absent; user data is interpolated directly into templates without explicit delimiters.
- Capability inventory: None; no code execution, file writing, or network capabilities are present in the skill.
- Sanitization: Absent.
- [METADATA_POISONING]: The skill metadata and documentation contain conflicting information.
- Evidence: The 'Skill Boundaries' section in 'SKILL.md' describes capabilities for 'audio production workflows' and 'audio engineering expertise,' which is unrelated to the 'Fundraising Narrative' content of the skill. Additionally, the author name differs between the YAML frontmatter ('ClawFu') and the bottom metadata block ('MKTG Skills'). these are likely non-malicious documentation errors.
Audit Metadata