consult-startup
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted user-supplied data to generate complex business documents and interacts with file-writing tools.
- Ingestion points: User-provided inputs for
{idea},{target_market},{team_info}, and{initial_capital}inSKILL.mdare interpolated directly into the workflow. - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to disregard potential instructions embedded within the user-provided startup data.
- Capability inventory: The skill has the capability to chain with
moai-officer:doc-xlsxandmoai-officer:doc-pptxto generate and save documents based on the processed input. - Sanitization: There is no evidence of input validation or sanitization logic to filter out adversarial instructions within the provided variables.
Audit Metadata