vc-pitch-deck
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data (startup narratives, evidence, and existing decks) which could contain hidden instructions designed to influence agent behavior.
- Ingestion points: External data enters the context through 'Step 1: Assemble the input sheet' and the 'Review / tear down' branch.
- Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the user-provided content.
- Capability inventory: The agent interacts with the
kb searchtool and performs text generation based on the potentially untrusted input. - Sanitization: There are no requirements for sanitizing or validating the ingested materials.
Audit Metadata