open-source-company-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of Markdown-based instructions and reference materials designed to guide an AI agent through a strategic business interview. There are no scripts, binaries, or platform-specific commands that could execute on a host machine.
  • [PROMPT_INJECTION]: No attempts to bypass AI safety filters, override system instructions, or extract system prompts were found. The instructional language is benign and professional.
  • [DATA_EXFILTRATION]: No network-enabled tools or commands (such as curl or wget) are present. The skill does not access sensitive local file paths like SSH keys, AWS credentials, or environment variables. All references to external files are local, relative links within the skill package (e.g., ./references/strategic-motives.md).
  • [OBFUSCATION]: The content is fully transparent. No Base64, zero-width characters, homoglyphs, or encoded payloads were detected in the instructions, metadata, or evaluation files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted user data during the strategy interview, the risk is negligible due to a lack of dangerous capabilities.
  • Ingestion points: The agent processes user responses to a 14-question strategy interview defined in SKILL.md.
  • Boundary markers: No explicit delimiters are used to separate user data from instructions, but the skill follows a strict step-by-step logic gate process.
  • Capability inventory: The agent has zero capability to execute shell commands, perform network requests, or write to the file system. Its output is limited to a strategy brief in Markdown format.
  • Sanitization: No explicit sanitization is present, but the lack of executable tools makes this surface non-exploitable.
  • [DYNAMIC_CONTEXT_INJECTION]: No usage of the dynamic context injection pattern (e.g., !command) was found in the SKILL.md or other files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — open-source-company-strategy