yc-3-building-your-founding-team

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely on local markdown reference files and user input to provide startup advice. No network exfiltration, unauthorized file access, or command execution patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface by taking user responses to interactive workbook questions and interpolating them into a final synthesis saved to a file. However, this is a core functional requirement and carries low risk as it does not involve executing the input or sending it to untrusted third parties.
  • Ingestion points: User responses via the AskUserQuestion tool.
  • Boundary markers: Not explicitly defined; relies on agent context separation.
  • Capability inventory: Reading local reference markdown files and writing assessment results to the knowledge/ directory.
  • Sanitization: Standard LLM processing of text responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 AM
Security Audit — agent-trust-hub — yc-3-building-your-founding-team