startup-fundraising
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown instructions and YAML configuration for an AI agent. It contains no executable code, shell scripts, binary files, or external dependencies. All logic is prompt-based and focused on business process guidance.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process financial claims and diligence data. While this creates a potential surface for indirect prompt injection, the skill includes comprehensive mitigation instructions: (1) Ingestion points: evidence registers, claim ledgers, and financial inputs; (2) Boundary markers: explicit requirements to label actual results versus modelled scenarios and separate audience-specific disclosure stages; (3) Capability inventory: the skill possesses no automated capabilities such as file-system writes, network calls, or subprocess execution; (4) Sanitization: mandatory redaction and aggregation of sensitive personal and corporate data.- [DATA_EXFILTRATION]: No patterns of data exfiltration or hardcoded credentials were identified. The skill explicitly prohibits taking external actions—such as contacting investors or sharing data-room access—without prior human authorization. It emphasizes a "least-privilege" access model for disclosure.
Audit Metadata