grow-business
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill suggests installing additional components from the author's repository using the command
npx skills add wondelai/skills. These are identified as vendor-owned resources. - [COMMAND_EXECUTION]: Instructions guide the agent to provide commands for global installation of supporting tools via
npxwith the--globalflag. - [DATA_EXFILTRATION]: No network exfiltration was detected. The skill specifically targets local storage in the
docs/directory for persisting business plans, marketing artifacts, and metrics. - [PROMPT_INJECTION]: The instructions do not contain any bypass attempts or safety overrides. It includes explicit ethical guidelines for the agent, requiring that scarcity claims and testimonials be verified as true.
- [INDIRECT_PROMPT_INJECTION]: The skill reads from local project documentation (e.g.,
MARKETING.md,OFFER.md) to maintain state across sessions. While this represents an ingestion surface for data, it is restricted to the user's project environment and uses predefined artifact templates.
Audit Metadata