yc-5-launching
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface due to its requirement to process external reference data and user input, though this is consistent with its educational purpose.
- Ingestion points: The skill reads transcript files from the
references/directory and accepts user input through theAskUserQuestiontool during the interactive workbook phase. - Boundary markers: The instructions do not specify explicit delimiters or boundary markers to isolate ingested content from the agent's internal logic.
- Capability inventory: The skill is authorized to write synthesized data and user responses to the
knowledge/yc-startup-school/directory. - Sanitization: There is no explicit evidence of output sanitization or validation of the input content before it is recorded in the knowledge base.
Audit Metadata