startup-pivoting

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE] (SAFE): The skill consists entirely of Markdown files providing instructions and templates. No Python, JavaScript, or shell scripts are present.- [Prompt Injection] (SAFE): No patterns of instruction override, jailbreak attempts, or system prompt extraction were found in any of the analyzed files.- [Data Exposure & Exfiltration] (SAFE): There are no hardcoded credentials, references to sensitive local file paths, or network operations (curl, wget, fetch) that could lead to data leakage.- [Remote Code Execution] (SAFE): The skill does not define any dependencies (requirements.txt, package.json) and does not attempt to download or execute remote content.- [Obfuscation] (SAFE): The text is clear Markdown with no evidence of Base64 encoding, zero-width characters, or homoglyph-based evasion techniques.- [Persistence & Privilege Escalation] (SAFE): No commands related to system persistence or administrative privilege acquisition were detected.- [Indirect Prompt Injection] (SAFE): While the skill ingests user input (metrics and feedback), it lacks any computational capabilities (tools, code execution, or network access) that would allow an attacker to exploit this ingestion surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:26 PM