go-to-market-plan-skill-founder

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on business analysis and strategy generation. It does not perform unauthorized network operations, access sensitive credentials, or execute arbitrary system commands.- [EXTERNAL_DOWNLOADS]: The skill metadata references its original source on GitHub for attribution and version tracking. These references are informative and do not involve runtime execution of untrusted remote code.- [PROMPT_INJECTION]: The skill processes business information from a local file (FOUNDER_CONTEXT.md). While this constitutes an attack surface for indirect prompt injection, the risk is negligible as the skill lacks high-privilege capabilities (such as shell execution or network writing) that could be abused by malicious data.
  • Ingestion points: FOUNDER_CONTEXT.md (Task Execution, Step 1).
  • Boundary markers: Absent; the skill relies on field extraction instructions rather than explicit delimiters.
  • Capability inventory: Limited to the AskUserQuestion tool for gathering founder input.
  • Sanitization: None; the skill assumes the context file is a valid business description provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:32 AM
Security Audit — agent-trust-hub — go-to-market-plan-skill-founder