cto-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed as a technical leadership advisor and engineering strategy framework. Analysis of the instructions and examples shows no malicious patterns, hardcoded credentials, or unauthorized persistence mechanisms. All analyzed content is consistent with the stated purpose of technical leadership guidance.\n- [COMMAND_EXECUTION]: The skill documents the execution of local Python scripts (tech_debt_analyzer.py and team_scaling_calculator.py) for analyzing technical debt and modeling team growth. These are legitimate helper tools for the skill's analytical functions and do not involve remote code downloads or suspicious shell piping.\n- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes external codebase descriptions through subagent tasks. \n
  • Ingestion points: Untrusted data enters via the {repo_or_description} placeholder in the multi-agent analysis workflows defined in SKILL.md.\n
  • Boundary markers: Instructions do not include explicit separators or guidelines for ignoring embedded commands in the repository descriptions.\n
  • Capability inventory: The skill utilizes script execution and multi-agent tasking capabilities to process data.\n
  • Sanitization: No sanitization or validation of the input strings is specified in the prompt logic. This is assessed as a low-risk surface associated with the skill's primary diagnostic purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — cto-advisor