dev-marketing-prospector

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a legitimate and transparent workflow for market research and data aggregation.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to gather information from a wide range of well-known and established public services such as Crunchbase, LinkedIn, GitHub, and various tech news outlets. These are used for data retrieval only and do not involve executing external code or scripts.
  • [DATA_EXFILTRATION]: No patterns of accessing sensitive local files, such as credentials, SSH keys, or environment variables, were found. The skill operates entirely on publicly available information and does not attempt to send data to unauthorized external endpoints.
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override the agent's system prompt, bypass safety guidelines, or extract internal instructions. The directives are strictly functional and task-oriented.
  • [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or privilege escalation attempts within the skill instructions or associated reference files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external websites, it specifies a narrow scope for data extraction (funding, headcount, outreach signals), which minimizes the risk of the agent executing adversarial instructions potentially embedded in those external pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 03:03 PM
Security Audit — agent-trust-hub — dev-marketing-prospector