companify-coo
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for organizational development, mapping delivery flows and critical processes into local markdown files. Its operations are confined to the local project environment.
- [INDIRECT_PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection because it ingests data from multiple local files which could be manipulated.
- Ingestion points: The skill reads
company/product.md,company/technology.md,company/finance.md, and.companify/progresso.md. - Boundary markers: No specific delimiters or instructions are provided to distinguish between data and potential instructions within these files.
- Capability inventory: The skill is capable of writing to the filesystem (
company/operations.md,.companify/progresso.md) and conducting iterative user interviews. - Sanitization: There is no evidence of sanitization or validation of the content read from the source files.
Audit Metadata