companify-interview
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input from interview responses and stores it in persistent context files.
- Ingestion points: User input gathered during the discovery steps and local files like .companify/config.yaml (SKILL.md).
- Boundary markers: No explicit delimiters or boundary markers for untrusted content are provided in the skill instructions.
- Capability inventory: The skill updates local project files (.companify/interview.md, .companify/progresso.md, .companify/company-context.md, .companify/assumptions.md) using agent file system tools. No network or arbitrary command execution capabilities were detected.
- Sanitization: No input validation or sanitization routines are specified for user-provided content before it is recorded in the project context.
Audit Metadata