guru-paul-graham
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as an educational and advisory interface. It leverages 14 local reference documents containing public essays to ground the agent's persona and logic in a specific philosophy.
- [DATA_EXPOSURE_EXFILTRATION]: The skill uses local file access to read its reference library and write user interaction results to a persistent knowledge file at
knowledge/yc-startup-school/guru-pg-workbook.md. These actions are within the expected behavior of a productivity skill and do not involve unauthorized network transmission or access to sensitive system secrets like SSH keys or cloud credentials. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user input regarding startup ideas to generate advice. 1. Ingestion points: User input provided during the interactive diagnostic questions in
SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Reading local markdown references and writing results toknowledge/yc-startup-school/guru-pg-workbook.md. 4. Sanitization: Absent. The vulnerability surface is restricted to the generated text output and the saved workbook, presenting no significant risk to the host environment or agent safety guidelines.
Audit Metadata