profitable-efficient-growth
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is to compute financial metrics (LTV:CAC, CAC payback, NRR, Rule of 40, Magic Number, and Burn Multiple) and provide strategic spend allocation recommendations. No patterns associated with prompt injection, credential theft, or unauthorized remote access were detected in the skill instructions or scripts.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources like financial models, board decks, and CRM systems, which creates a theoretical surface for indirect prompt injection.
- Ingestion points: Data is sourced from uploaded files and integrated business tools as outlined in the 'Inputs you need' section.
- Boundary markers: The agent is not instructed to use specific markers or delimiters to isolate untrusted data, though the risk is naturally mitigated by the quantitative nature of the analysis.
- Capability inventory: The skill is limited to performing mathematical operations and text report generation; it does not have capabilities for persistent storage, system modification, or network requests.
- Sanitization: The instructions prioritize the accuracy and provenance of the financial figures over security-based sanitization of the document content.
Audit Metadata