skills/iwanhe/pandawa/ceo-advisor/Gen Agent Trust Hub

ceo-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate executive advisory tool. The logic contained within strategy_analyzer.py and financial_scenario_analyzer.py is restricted to mathematical processing of input data. The scripts use only Python standard libraries and do not perform any network operations, sensitive file access, or command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest external context, creating a surface for indirect prompt injection.
  • Ingestion points: Instructions in SKILL.md direct the agent to read company-context.md before responding.
  • Boundary markers: There are no explicit delimiters or specific instructions provided to the agent to differentiate between the context file content and core system instructions.
  • Capability inventory: The skill utilizes Python scripts for strategic and financial scoring. No capabilities exist for network exfiltration, file writing, or shell command execution.
  • Sanitization: No data sanitization or validation logic is applied to the ingested context data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — ceo-advisor