oss-sponsors-brand-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from project manifests, lockfiles, and FUNDING.yml files (as specified in SKILL.md and references/target-discovery-and-scoring.md) to map dependencies and identify funding targets.
  • Ingestion points: Local file manifests such as SBOMs, lockfiles, and remote FUNDING.yml files.
  • Boundary markers: The skill does not explicitly define delimiters or instructions to ignore embedded prompts within these files.
  • Capability inventory: The skill utilizes the agent's network capabilities to fetch metadata from APIs and verify the existence of external URLs.
  • Sanitization: There is no mention of sanitizing or validating the contents of the manifests or metadata before processing.
  • [EXTERNAL_DOWNLOADS]: The skill performs necessary network operations to fulfill its primary function.
  • It fetches dependency and health metadata from well-known services, including Google's deps.dev API and the GitHub API.
  • It verifies external funding URLs discovered in project manifests by attempting to fetch them and checking for redirects or errors. These network activities are documented as core steps in the portfolio building process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — oss-sponsors-brand-strategy