vc-ai-infra-scout
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves data from established search and enrichment services including Tavily, Parallel, Exa, and Apollo. These integrations are essential for the startup discovery workflow and are conducted via documented API endpoints.
- [PROMPT_INJECTION]: The skill processes untrusted external content from public social media and forums, which presents an indirect prompt injection surface. This is a baseline risk for search-oriented skills and is mitigated by the lack of high-privilege capabilities such as local file writing or arbitrary command execution.
- [COMMAND_EXECUTION]: Network operations are executed using the selat-pay utility to make structured API calls. The usage is strictly parameterized for data fetching from defined service providers and does not involve system-level shell execution of untrusted input.
Audit Metadata