event-sponsor-prospectus

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided event details to generate a sponsorship prospectus. While this involves processing external data, the skill includes robust safety logic in its 'Honesty sweep' and 'Failure modes' sections that explicitly instructs the agent to reject deceptive requests (e.g., manufacturing scarcity, printing false guarantees, or disclosing attendee contact lists at community events). This mitigates risks associated with adversarial user input.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were identified. The skill correctly references its sibling tools using the author's own ecosystem patterns (e.g., samber/dev-event-organizer-skills).
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code execution, package installations, or dynamic code evaluation. It is strictly limited to text generation and document structuring.
  • [SAFE]: The skill follows best practices for secret management (referencing sibling skills for sensitive pricing) and does not utilize any obfuscation, persistence, or privilege escalation techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-sponsor-prospectus