vc-pitch-deck

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (startup narratives, evidence, and existing decks) which could contain hidden instructions designed to influence agent behavior.
  • Ingestion points: External data enters the context through 'Step 1: Assemble the input sheet' and the 'Review / tear down' branch.
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the user-provided content.
  • Capability inventory: The agent interacts with the kb search tool and performs text generation based on the potentially untrusted input.
  • Sanitization: There are no requirements for sanitizing or validating the ingested materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:50 PM
Security Audit — agent-trust-hub — vc-pitch-deck