fundraising-optimizer

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted codebase files, such as schema definitions and project configurations, to perform its fundraising analysis. This creates a surface for indirect prompt injection where instructions embedded in the analyzed code could influence the agent's behavior.
  • Ingestion points: Reads various project files including package.json, requirements.txt, schema definitions, and ORM models (SKILL.md).
  • Boundary markers: Absent. No specific delimiters or warnings are used when processing the codebase content.
  • Capability inventory: The agent has autonomous file reading capabilities and is instructed to write telemetry to ~/.claude/projects/.
  • Sanitization: Absent. No evidence of content sanitization or validation before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — fundraising-optimizer