vc-finder

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands and Python scripts to perform data processing, such as regex-based signal detection for funding stages and scoring logic for matching startups against its internal venture capital dataset.
  • [EXTERNAL_DOWNLOADS]: The skill fetches product information from user-provided URLs and retrieves search results from well-known technology services (Tavily and Firecrawl). These operations are essential to its core research functionality.
  • [DATA_INGESTION_SURFACE]: The skill processes untrusted content from external websites (startup homepages). While this presents an indirect prompt injection surface, the risk is minimized by the skill's structured processing logic and strict factual extraction requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:04 PM
Security Audit — agent-trust-hub — vc-finder