yc-1-deciding-to-start-a-startup

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill's instructions, frontmatter, and reference materials reveals no malicious code, unauthorized network calls, or credential harvesting. The skill correctly limits its scope to reading local transcript files and interacting with the user through standard platform tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and synthesizes user-provided responses during the workbook phase.
  • Ingestion points: User responses collected via the AskUserQuestion tool in SKILL.md.
  • Boundary markers: None are explicitly used in the prompt template to separate user input from instructional synthesis.
  • Capability inventory: The skill is limited to writing interaction summaries to the local knowledge/ directory.
  • Sanitization: No explicit sanitization of user-provided content is performed before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 AM
Security Audit — agent-trust-hub — yc-1-deciding-to-start-a-startup