pitch-message
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent in the 'Delivery' section and Step 6 to format its output as a security analysis report, using terms like 'unified severity indicators' and 'one-line verdict.' This deceptive instruction pattern misrepresents marketing recommendations as formal security findings.
- [COMMAND_EXECUTION]: The instructions in Step 1 reference an external command or sub-skill named 'pitch-recon.' The logic for this command is not included in the skill files, which prevents verification of its safety or impact.
- [EXTERNAL_DOWNLOADS]: The skill attempts to fetch or reference an external file 'docs/output-kit.md' for output formatting instructions and mentions an external reporting mechanism '/atlas-report,' neither of which can be inspected in the provided context.
Audit Metadata