ceo-companion

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • EXTERNAL_DOWNLOADS (LOW): The skill installs the 'brainstorming' skill from 'github.com/obra/superpowers'. This repository is not on the pre-approved trusted list.
  • COMMAND_EXECUTION (LOW): Use of the '-y' flag with 'npx skills add' allows the skill to install dependencies without manual user approval, bypassing a security checkpoint.
  • EXTERNAL_DOWNLOADS (SAFE): The dependency 'find-skills' is sourced from 'vercel-labs', a trusted organization, which downgrades this specific finding per the [TRUST-SCOPE-RULE].
  • PROMPT_INJECTION (LOW): Indirect Prompt Injection surface (Category 8) detected: 1. Ingestion points: Processes untrusted live web content via WebSearch and WebFetch tools. 2. Boundary markers: Absent; the skill does not specify delimiters to separate untrusted web data from its own instructions. 3. Capability inventory: The skill writes structured research output to files in the '.strategy/' directory which are intended to be executed/read by a downstream 'Beads Orchestration' skill. 4. Sanitization: Absent; no validation or filtering of external content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:18 PM