pitch-deck

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a template-based narrative generation workflow that relies on local reference files and user interaction.
  • [PROMPT_INJECTION]: The skill reads information from local project files (.claude/context/idea.md and .claude/context/build.md) to pre-fill the interview questions. While it lacks explicit boundary markers or sanitization for this ingested data, it does not possess any dangerous capabilities such as network access, shell command execution, or file writing permissions. Evidence: 1. Ingestion points: Local workspace files .claude/context/idea.md and .claude/context/build.md. 2. Boundary markers: Absent. 3. Capability inventory: No subprocess calls, file-write operations, or network requests are present in the skill instructions. 4. Sanitization: Absent. Due to the restricted capability set, this surface does not pose a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 05:34 PM
Security Audit — agent-trust-hub — pitch-deck