startup-pitch-contest
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of markdown documentation, guidelines, and evaluation templates. There are no executable scripts, system commands, or network operations included in the skill package.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for collecting and reviewing data from external startup applicants. While this ingestion of untrusted data creates a theoretical surface for indirect prompt injection, the skill lacks technical capabilities to act on malicious instructions. 1. Ingestion points: Application form fields defined in references/application-and-slate-mechanics.md. 2. Boundary markers: Absent. 3. Capability inventory: No command execution, network calls, or file-writing capabilities were identified across all referenced files. 4. Sanitization: Not applicable as the skill functions as a procedural reasoning framework for organizers rather than an automated data processor.
Audit Metadata