startup-validator

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection during the market research phase. It instructs the agent to fetch and analyze full articles from various external websites using web_fetch without providing instructions to isolate this untrusted content from the system prompt.\n
  • Ingestion points: External URLs and industry reports retrieved via the web_fetch tool as described in Step 3 of the workflow in SKILL.md.\n
  • Boundary markers: Absent; the agent is not directed to use delimiters (like XML tags or triple quotes) to wrap fetched content, nor are there instructions to ignore instructions contained within the fetched data.\n
  • Capability inventory: The skill has the ability to perform further web searches and execute a local Python script for data processing.\n
  • Sanitization: No sanitization or filtering logic is defined for the content retrieved from the web before it is analyzed by the agent.\n- [COMMAND_EXECUTION]: The skill utilizes a bundled Python script (scripts/market_analyzer.py) for quantitative calculations. While the script is static and performs benign mathematical operations, the execution of local scripts using data-derived JSON files is a notable behavior.\n
  • Evidence: Step 4 in SKILL.md describes the optional use of python scripts/market_analyzer.py analysis_data.json to calculate metrics and generate reports based on gathered data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — startup-validator