skills/lijigang/ljg-skills/ljg-invest/Gen Agent Trust Hub

ljg-invest

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as business plans, founder conversation records, and meeting notes. These sources could contain malicious instructions designed to subvert the agent's logic during the analysis phase.
  • Ingestion points: External project materials including pitch decks, conversation records, and data fetched via the Research skill as specified in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill utilizes a Write tool to create files in ~/Documents/notes/ and a Research skill for external data gathering.
  • Sanitization: No sanitization, validation, or escaping of the external content is specified before processing.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use a file system Write tool to save output to a predefined path (~/Documents/notes/). While this is for report generation, it involves automated file system interaction based on external input naming.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:51 PM
Security Audit — agent-trust-hub — ljg-invest