startup-analyst
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection where malicious instructions could be embedded in external data sources.
- Ingestion points: The agent is instructed to use web search for current market data, competitive intelligence gathering, and industry trend identification (SKILL.md).
- Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings for the agent when processing content retrieved from the web.
- Capability inventory: The agent has capabilities to perform web searches, execute calculations, and write documents/reports (SKILL.md).
- Sanitization: There is no mention of sanitization, validation, or filtering of external content before it is processed or included in analyses.
Audit Metadata