yc-5-launching

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface due to its requirement to process external reference data and user input, though this is consistent with its educational purpose.
  • Ingestion points: The skill reads transcript files from the references/ directory and accepts user input through the AskUserQuestion tool during the interactive workbook phase.
  • Boundary markers: The instructions do not specify explicit delimiters or boundary markers to isolate ingested content from the agent's internal logic.
  • Capability inventory: The skill is authorized to write synthesized data and user responses to the knowledge/yc-startup-school/ directory.
  • Sanitization: There is no explicit evidence of output sanitization or validation of the input content before it is recorded in the knowledge base.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 AM
Security Audit — agent-trust-hub — yc-5-launching