oss-sponsors-fundraising

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not attempt to override safety filters or bypass system guidelines. The instructional language is professional and focused on its stated purpose of sponsorship strategy advice.
  • [DATA_EXFILTRATION]: No network operations or commands to access sensitive system files were detected. The skill references well-known services like GitHub and Tidelift for informational purposes, which is consistent with its domain.
  • [OBFUSCATION]: There is no evidence of hidden content, Base64-encoded strings, zero-width characters, or homoglyph attacks. All content is in plain-text markdown.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads or script executions. It is a documentation-based skill with no active command patterns.
  • [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic shell execution syntax (!command``) was found within the instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user input through a structured interview process, it possesses no dangerous capabilities (such as file writes or network access) that could be exploited through malicious user data. The risk surface is effectively null.
  • [METADATA_POISONING]: The metadata correctly identifies the author and version, and it is consistent with the vendor identity (samber). The descriptions accurately reflect the functionality found in the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — oss-sponsors-fundraising