skills/ooiyeefei/ccc/pitch-package/Gen Agent Trust Hub

pitch-package

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured workflow for project management and presentation planning. It does not contain any executable scripts, network requests, or sensitive file access.\n- [COMMAND_EXECUTION]: Documentation in references/stitching.md provides ffmpeg command examples for local video processing. These are standard tools for the described task and do not pose a security risk as they are provided as static instructional content for handling local media assets.\n- [PROMPT_INJECTION]: The skill uses instructional markers like 'STOP' to maintain a specific workflow sequence. These are benign and intended to ensure the agent gathers necessary information before generating artifacts, rather than attempting to bypass safety filters.\n- [SAFE]: The skill processes user input regarding audience and inventory in Phase 1. 1. Ingestion points: User-provided pitch details in SKILL.md. 2. Boundary markers: The instructions mandate a confirmation step ('get a nod') before moving to Phase 2. 3. Capability inventory: No direct subprocess or file-system writing capabilities are defined in this specific skill. 4. Sanitization: None explicitly defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:45 AM
Security Audit — agent-trust-hub — pitch-package