ma-playbook

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured methodology for business acquisitions and readiness assessments, providing checklists for financial, technical, and legal due diligence.
  • [COMMAND_EXECUTION]: The multi-agent section utilizes a Task orchestration syntax to delegate research activities. These tasks are scoped to information gathering from public sources and do not allow for arbitrary shell command execution.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it interpolates user-provided data into sub-agent prompts.
  • Ingestion points: {target_company}, {category}, and {buyer_type} placeholders in SKILL.md are populated by user input.
  • Boundary markers: None identified; inputs are interpolated directly into the research prompt strings.
  • Capability inventory: The sub-agents perform external research and planning tasks, but do not have file-write or system-level capabilities.
  • Sanitization: No explicit validation or sanitization of input placeholders is present in the prompt templates.
  • [DATA_EXFILTRATION]: No unauthorized data access or external transmission of sensitive information was detected. The research activities target public profiles and platforms as intended by the skill's business purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — ma-playbook