cto-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions and workflows for a CTO role, using standard technical methodologies like ReAct and ADRs. No security violations were found.
  • [COMMAND_EXECUTION]: The skill references local scripts (scripts/tech_debt_analyzer.py, scripts/team_scaling_calculator.py) for specific assessments. These are part of the skill's intended functionality and do not involve remote downloads or privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingest data from company-context.md to provide context-aware advice. This represents a vulnerability surface typical for specialized AI agents.
  • Ingestion points: company-context.md
  • Boundary markers: Absent; instructions do not explicitly define delimiters for external data.
  • Capability inventory: Local script execution via python commands.
  • Sanitization: Not explicitly mentioned in the provided markdown file.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — cto-advisor