partnerships-kickoff

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project files to build a long-term context artifact, creating a vector for instructions embedded in those files to influence future agent sessions.
  • Ingestion points: Reads file inventory including README, agent-instruction files, partner agreements, and program documents as specified in SKILL.md Section 1.
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded prompts when reading these external files.
  • Capability inventory: The skill updates the partnerships-context.md file, modifies persistent memory stores, and can optionally patch project-level agent-instruction files.
  • Sanitization: Section 6 of SKILL.md provides explicit instructions to exclude PII, contact lists, and negotiated rates from memory, reducing the risk of data exfiltration via shared stores.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — partnerships-kickoff