yc-6-growing-and-monetizing

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves an educational purpose, providing startup frameworks and a workbook based on YC Startup School lectures. All external links point to well-known, trusted platforms (YouTube and YCombinator).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted user input to generate synthesis reports and feedback.
  • Ingestion points: User answers provided through the AskUserQuestion tool in the interactive workbook section of SKILL.md.
  • Boundary markers: None (The instructions do not specify the use of delimiters or 'ignore' instructions for the user-supplied content).
  • Capability inventory: The skill has the capability to write files to the local knowledge/ directory (e.g., knowledge/yc-startup-school/module-6-assessment.md).
  • Sanitization: None (There is no explicit logic to sanitize or validate the user responses before synthesis).
  • Context: As the skill's capabilities are limited to local knowledge storage and the ingestion is central to its primary purpose (a self-assessment workbook), this is categorized as a standard, low-risk surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 AM
Security Audit — agent-trust-hub — yc-6-growing-and-monetizing