companify-cro
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No executable code or scripts are included in this skill; it consists solely of Markdown and YAML documentation.
- [SAFE]: No network access, external downloads, or remote code execution patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an ingestion surface by reading content from local files (business-model.md, marketing.md, finance.md, product.md) as specified in SKILL.md. This content is then used to generate company/revenue.md. Evidence: 1. Ingestion points: .companify/progresso.md, company/business-model.md, company/marketing.md, company/finance.md, company/product.md. 2. Boundary markers: Absent. 3. Capability inventory: File reading and writing within the workspace. 4. Sanitization: Absent. This is considered a low-risk surface as it involves local workspace files rather than untrusted remote data.
Audit Metadata