investor-research

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill's instructions are limited to its stated purpose of venture capital research and do not attempt to bypass agent safety guidelines.
  • [DATA_EXFILTRATION]: No network activity or access to sensitive local files (like SSH keys or environment variables) was found in the scripts or instructions.
  • [REMOTE_CODE_EXECUTION]: The Python script performs basic file input/output and string formatting. It does not use functions like eval() or subprocess to execute code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON data to generate a report. While this is an ingestion surface for untrusted data, the risk is low as the output is intended as a static document for human review.
  • [OBFUSCATION]: No hidden URLs, encoded commands, or deceptive character techniques were found in the skill's files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 07:32 PM
Security Audit — agent-trust-hub — investor-research