funding-digest
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of 'simple-icons' and 'sharp' Node.js packages for brand logo management and image processing. It also utilizes the 'markitdown' library, which is a reputable package from Microsoft. These external resources are standard in the industry and originate from trusted or well-known sources.
- [COMMAND_EXECUTION]: The workflow involves executing various system commands and scripts, including 'npm', 'python', and 'pdftoppm'. These are used for legitimate purposes such as package management, document conversion (via a LibreOffice wrapper), and generating slide previews.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from external S&P Global tools. Ingestion points: Data enters the context from tool outputs such as 'get_rounds_of_funding_info_from_transaction_ids'. Boundary markers: The skill does not currently employ explicit boundary markers or instructions to ignore embedded commands within the ingested data. Capability inventory: The skill has permissions for file system writes and shell command execution. Sanitization: The skill does not explicitly sanitize company names or descriptions before interpolating them into the PowerPoint generation logic.
Audit Metadata