startup-channel-finder

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill was audited across all threat categories and no malicious patterns were detected. It adheres to the provided research playbook which emphasizes safe and respectful data collection.
  • [COMMAND_EXECUTION]: The skill instructions involve running local Python scripts (score_channels.py and generate_report.py) to process research data. These scripts use standard Python libraries and perform validation on inputs, posing no risk to the environment.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection through the ingestion of untrusted external content from URLs and repositories. This is mitigated by the structured nature of the analysis and the lack of dangerous autonomous capabilities.
  • Ingestion points: Inspection of supplied URLs, repositories, and landing pages.
  • Boundary markers: Instructions provided to separate facts from inferences.
  • Capability inventory: Writing research results to JSON, MD, and CSV files and executing local validation scripts.
  • Sanitization: URL schema validation and Markdown character escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 10:40 PM
Security Audit — agent-trust-hub — startup-channel-finder