startup-analyst

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection where malicious instructions could be embedded in external data sources.
  • Ingestion points: The agent is instructed to use web search for current market data, competitive intelligence gathering, and industry trend identification (SKILL.md).
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings for the agent when processing content retrieved from the web.
  • Capability inventory: The agent has capabilities to perform web searches, execute calculations, and write documents/reports (SKILL.md).
  • Sanitization: There is no mention of sanitization, validation, or filtering of external content before it is processed or included in analyses.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:21 AM
Security Audit — agent-trust-hub — startup-analyst