business-growth-skills

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation identifies capabilities for processing external business documents which represent an untrusted data ingestion surface. Maliciously crafted documents could attempt to influence the agent's analysis or output.\n
  • Ingestion points: Business files such as Request for Proposal (RFP) documents, contracts, and pipeline data mentioned in the skill overview.\n
  • Boundary markers: The provided index file does not specify delimiters or instruction-ignore warnings for processed data.\n
  • Capability inventory: Mentions Python scripts for automated health scoring and pipeline analysis.\n
  • Sanitization: No sanitization or validation methods are described in the top-level documentation.\n- [EXTERNAL_DOWNLOADS]: The Quick Start section provides instructions for users to download additional skill components from a GitHub repository via a CLI tool (agent-skills-cli). while these are manual user instructions, they involve fetching content from an external third-party source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:32 PM
Security Audit — agent-trust-hub — business-growth-skills