startup-canvas

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed of natural language instructions for product strategy and does not contain any executable scripts, binaries, or system commands.- [SAFE]: External references point to informational content on 'productcompass.pm' and a public Google Slides template, which are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill interpolates user-provided data via the $ARGUMENTS variable. Analysis of this surface shows: Ingestion point is the $ARGUMENTS variable; Boundary markers are absent; Capability inventory confirms no access to tools, network, or file system; Sanitization is absent. Despite the ingestion of untrusted data, the lack of functional capabilities makes this surface benign.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:28 PM
Security Audit — agent-trust-hub — startup-canvas