yc-3-building-your-founding-team
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely on local markdown reference files and user input to provide startup advice. No network exfiltration, unauthorized file access, or command execution patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface by taking user responses to interactive workbook questions and interpolating them into a final synthesis saved to a file. However, this is a core functional requirement and carries low risk as it does not involve executing the input or sending it to untrusted third parties.
- Ingestion points: User responses via the
AskUserQuestiontool. - Boundary markers: Not explicitly defined; relies on agent context separation.
- Capability inventory: Reading local reference markdown files and writing assessment results to the
knowledge/directory. - Sanitization: Standard LLM processing of text responses.
Audit Metadata