ceo-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any malicious patterns. No unauthorized network requests, shell command executions, or hardcoded credentials were found across the instructions, reference documents, or Python scripts.
  • [DATA_EXPOSURE]: While the skill is designed to process sensitive executive data such as company financials and strategic plans, there is no evidence of unauthorized data harvesting or exfiltration to external domains. Access is limited to local files like 'company-context.md' as required for the skill's primary function.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an ingestion surface for external data via 'company-context.md'. However, the risk is mitigated as the skill's scripts lack dangerous capabilities such as network access, arbitrary command execution (exec/eval), or file system write operations.
  • [COMMAND_EXECUTION]: The provided Python scripts ('strategy_analyzer.py' and 'financial_scenario_analyzer.py') use standard libraries for mathematical calculations and logic, avoiding any calls to system shells or subprocesses.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:15 AM
Security Audit — agent-trust-hub — ceo-advisor