yc-7-fundraising-and-company-building

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to process provided educational transcripts from Y Combinator's Startup School and generate a structured self-assessment for the user.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No evidence of sensitive data access or unauthorized network activity was found. The skill operates on its own reference files and saves output to a standard knowledge directory within the agent's environment.
  • [COMMAND_EXECUTION]: The instructions do not contain any shell commands, subprocess calls, or system-level modifications. The use of the AskUserQuestion tool is appropriate for the skill's interactive educational purpose.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user input via the interactive workbook, it does so within a controlled educational framework and does not pull data from untrusted external web sources, minimizing the risk of indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 AM
Security Audit — agent-trust-hub — yc-7-fundraising-and-company-building