companify-builder
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from workspace files which serves as an attack surface for indirect prompt injection.
- Ingestion points: The skill instructions specifically require reading data from
.companify/company-context.md,.companify/config.yaml,.brandfy/config.yaml, andbrand/strategy.mdto establish company context. - Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings when interpolating content from these project files into the agent context.
- Capability inventory: The skill has broad orchestration capabilities, invoking numerous specialized agents (CEO, CPO, CTO, etc.) and writing consolidated business strategy artifacts to the
company/directory. - Sanitization: There is no evidence of validation or sanitization of the content ingested from the local workspace files before it is processed by the agent.
Audit Metadata