ai-readiness
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection surface detected through the use of external data sources.
- Ingestion points: The skill is designed to ingest data from external MCP servers including PitchBook, S&P Global, and FactSet to perform assessments.
- Boundary markers: The skill instructions do not provide the agent with specific delimiters or warnings to ignore commands or instructions that might be contained within the data retrieved from these sources.
- Capability inventory: The skill processes the ingested information to calculate scores and generate strategic roadmaps. While no dangerous shell commands were found in the skill text, the lack of input control allows for potential manipulation of the agent's logic.
- Sanitization: There is no evidence of validation, escaping, or sanitization of the content fetched from external sources before it is processed.
Audit Metadata