startup-business-analyst-business-case

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting untrusted data from the user and potentially external documents.
  • Ingestion points: Step 1 gathers company basics, elevator pitches, and existing materials (pitch decks or docs) from the user or file system.
  • Boundary markers: Absent. The instructions do not define delimiters or specific 'ignore embedded instructions' warnings for the processing of these inputs.
  • Capability inventory: The skill has access to powerful tools including Bash, Read, Write, Edit, WebSearch, and WebFetch.
  • Sanitization: Absent. There is no mention of escaping, validating, or filtering the content provided by the user before it is integrated into the final document structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 06:59 AM