startup-validator
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection during the market research phase. It instructs the agent to fetch and analyze full articles from various external websites using
web_fetchwithout providing instructions to isolate this untrusted content from the system prompt.\n - Ingestion points: External URLs and industry reports retrieved via the
web_fetchtool as described in Step 3 of the workflow inSKILL.md.\n - Boundary markers: Absent; the agent is not directed to use delimiters (like XML tags or triple quotes) to wrap fetched content, nor are there instructions to ignore instructions contained within the fetched data.\n
- Capability inventory: The skill has the ability to perform further web searches and execute a local Python script for data processing.\n
- Sanitization: No sanitization or filtering logic is defined for the content retrieved from the web before it is analyzed by the agent.\n- [COMMAND_EXECUTION]: The skill utilizes a bundled Python script (
scripts/market_analyzer.py) for quantitative calculations. While the script is static and performs benign mathematical operations, the execution of local scripts using data-derived JSON files is a notable behavior.\n - Evidence: Step 4 in
SKILL.mddescribes the optional use ofpython scripts/market_analyzer.py analysis_data.jsonto calculate metrics and generate reports based on gathered data.
Audit Metadata