oss-sponsors-fundraising
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions do not attempt to override safety filters or bypass system guidelines. The instructional language is professional and focused on its stated purpose of sponsorship strategy advice.
- [DATA_EXFILTRATION]: No network operations or commands to access sensitive system files were detected. The skill references well-known services like GitHub and Tidelift for informational purposes, which is consistent with its domain.
- [OBFUSCATION]: There is no evidence of hidden content, Base64-encoded strings, zero-width characters, or homoglyph attacks. All content is in plain-text markdown.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads or script executions. It is a documentation-based skill with no active command patterns.
- [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic shell execution syntax (
!command``) was found within the instructions. - [INDIRECT_PROMPT_INJECTION]: While the skill ingests user input through a structured interview process, it possesses no dangerous capabilities (such as file writes or network access) that could be exploited through malicious user data. The risk surface is effectively null.
- [METADATA_POISONING]: The metadata correctly identifies the author and version, and it is consistent with the vendor identity (samber). The descriptions accurately reflect the functionality found in the content.
Audit Metadata