operations

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions and reference materials confirms they are focused on operational guidance for startup founders. No malicious code, data exfiltration, or obfuscation patterns were identified.
  • [SAFE]: The binary assets, assets/Investor_update_template.docx and assets/OKR_Example_Tracker.xlsx, are standard office templates used for operational reporting and tracking, with no evidence of malicious payloads.
  • [PROMPT_INJECTION]: The skill integrates user-provided data (e.g., startup descriptions and goals) into operational templates, creating an indirect prompt injection surface. This is a low-risk, standard design for document-generating AI skills.
  • Ingestion points: User inputs for job roles, company details, and performance goals in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: Interacts with file-writing tools (docx, xlsx, pptx) to produce deliverables.
  • Sanitization: No explicit sanitization or filtering logic is defined for the user-supplied content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 02:22 PM
Security Audit — agent-trust-hub — operations