startup-analyst

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and process untrusted data from external sources.
  • Ingestion points: The skill instructions specify the use of web search for gathering current market data, competitive intelligence, and industry trends (SKILL.md).
  • Boundary markers: The skill lacks explicit delimiters or instructions to the model to ignore or treat as data any natural language instructions that might be embedded within the results of web searches or external reports.
  • Capability inventory: The agent has the capability to write documents, perform financial calculations, and invoke other plugin commands such as /financial-projections and /business-case (SKILL.md).
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from external sources before it is processed by the agent's core logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 04:39 PM
Security Audit — agent-trust-hub — startup-analyst