investor-relations
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines strict data isolation and confidentiality boundaries, instructing the agent to omit credentials, private relationship details, and sensitive financial data from reusable outputs.
- [PROMPT_INJECTION]: The skill processes external information regarding investor profiles and meeting feedback, creating a surface for indirect prompt injection. This is mitigated by the skill's internal controls and lack of dangerous tools.
- Ingestion points: Untrusted data enters via investor fit records and meeting notes (references/targeting-meetings.md), and update contracts (references/updates-cadence.md).
- Boundary markers: Instructions require tagging data with
permitted_audienceandconfidentiality_basis. - Capability inventory: The skill lacks active tools or script execution capabilities; its primary function is generating structured drafts and reports.
- Sanitization: The workflow requires immutable versioning, legal review, and explicit authorization gates before any data is sent.
Audit Metadata