ceo-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate executive advisory tool. The logic contained within
strategy_analyzer.pyandfinancial_scenario_analyzer.pyis restricted to mathematical processing of input data. The scripts use only Python standard libraries and do not perform any network operations, sensitive file access, or command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest external context, creating a surface for indirect prompt injection.
- Ingestion points: Instructions in
SKILL.mddirect the agent to readcompany-context.mdbefore responding. - Boundary markers: There are no explicit delimiters or specific instructions provided to the agent to differentiate between the context file content and core system instructions.
- Capability inventory: The skill utilizes Python scripts for strategic and financial scoring. No capabilities exist for network exfiltration, file writing, or shell command execution.
- Sanitization: No data sanitization or validation logic is applied to the ingested context data.
Audit Metadata