fundraising-optimizer
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted codebase files, such as schema definitions and project configurations, to perform its fundraising analysis. This creates a surface for indirect prompt injection where instructions embedded in the analyzed code could influence the agent's behavior.
- Ingestion points: Reads various project files including package.json, requirements.txt, schema definitions, and ORM models (SKILL.md).
- Boundary markers: Absent. No specific delimiters or warnings are used when processing the codebase content.
- Capability inventory: The agent has autonomous file reading capabilities and is instructed to write telemetry to ~/.claude/projects/.
- Sanitization: Absent. No evidence of content sanitization or validation before processing.
Audit Metadata