pggraham-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and provides a framework for the agent to adopt a specific analytical persona (Paul Graham). No executable scripts or binary files are included in the package.
  • [EXTERNAL_DOWNLOADS]: The skill includes an installation instruction using npx skills add, which is the standard mechanism for adding skills in this platform's ecosystem. The package name nuwa-skills/pggraham-skill corresponds to the skill's official author.
  • [SAFE]: All external URLs referenced in the documentation and references (such as paulgraham.com, github.com, and news.ycombinator.com) are well-known, legitimate sources related to the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user startup ideas for analysis, creating a surface for indirect prompt injection. However, the skill lacks capabilities for file writing, network exfiltration, or command execution, rendering the risk minimal. No sensitive interpolation patterns or missing boundary markers were found that would escalate this beyond the baseline risk of any LLM-based analysis tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 06:42 PM
Security Audit — agent-trust-hub — pggraham-perspective