gauntlet

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local script located at scripts/graph-audit as part of its mandatory filing process to verify the integrity of business records updated during a session.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user pitches and processes local 'vault' data, which serves as a surface for indirect prompt injection.
  • Ingestion points: Processes arbitrary user-supplied pitch text and reads from various local files in the wiki/ directory during its analysis and advisor board phases.
  • Boundary markers: The agent follows a 'Durable claim admission gate' protocol that mandates the verification of claims by reopening source files and quoting exact supporting passages before they are recorded as facts.
  • Capability inventory: File writing access to the wiki/initiatives/, index.md, and log.md files, alongside execution of the graph-audit integrity tool.
  • Sanitization: Uses explicit confidence labels like Founder-stated: unverified to demarcate and isolate user-supplied claims from verified system data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 04:14 AM
Security Audit — agent-trust-hub — gauntlet