startup-business-analyst-business-case

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill is designed to handle sensitive business information, including financial projections (ARR, MRR, burn rate), customer data, team equity structures, and intellectual property details. While this is expected for a business analyst tool, users should be aware that this data is processed by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection due to its processing of untrusted user input.
  • Ingestion points: Step 1 gathers company basics, audience goals, and existing materials from the user.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions embedded within the user-provided context.
  • Capability inventory: The skill references other internal agent skills for market sizing and financial modeling and includes the ability to save the resulting business case to a local markdown file.
  • Sanitization: Absent; the skill does not specify filtering or validation steps for the incoming user data before it is interpolated into the business case structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 02:31 PM
Security Audit — agent-trust-hub — startup-business-analyst-business-case