gauntlet
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local script located at
scripts/graph-auditas part of its mandatory filing process to verify the integrity of business records updated during a session. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user pitches and processes local 'vault' data, which serves as a surface for indirect prompt injection.
- Ingestion points: Processes arbitrary user-supplied pitch text and reads from various local files in the
wiki/directory during its analysis and advisor board phases. - Boundary markers: The agent follows a 'Durable claim admission gate' protocol that mandates the verification of claims by reopening source files and quoting exact supporting passages before they are recorded as facts.
- Capability inventory: File writing access to the
wiki/initiatives/,index.md, andlog.mdfiles, alongside execution of thegraph-auditintegrity tool. - Sanitization: Uses explicit confidence labels like
Founder-stated: unverifiedto demarcate and isolate user-supplied claims from verified system data.
Audit Metadata