investor-management-skill

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected. The skill's instructions are limited to parsing and organizing data for the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external tools such as CRMs and spreadsheets, which constitutes a potential vulnerability surface if those sources contain malicious instructions.
  • Ingestion points: Data is pulled from "CRM" and "cap table / spreadsheet" as specified in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or "ignore" warnings to distinguish external data from core instructions.
  • Capability inventory: The skill's actions are restricted to data parsing, formatting, and template output within the chat context.
  • Sanitization: No sanitization or validation of the ingested external content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:32 AM
Security Audit — agent-trust-hub — investor-management-skill