NYC

cto-advisor

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOWPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION] (INFO): The skill references the execution of local scripts ('scripts/tech_debt_analyzer.py', 'scripts/team_scaling_calculator.py') to perform technical debt and scaling analysis. While these files were not provided for analysis, their described use cases are consistent with the skill's management-oriented purpose.
  • [INDIRECT_PROMPT_INJECTION] (LOW): The skill's core functions include analyzing external inputs like architecture specifications and vendor responses, which presents an indirect injection surface. 1. Ingestion points: Architecture decision records and technology evaluation frameworks in references/architecture_decision_records.md and references/technology_evaluation_framework.md. 2. Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the templates. 3. Capability inventory: Capability to execute local analysis scripts as defined in SKILL.md. 4. Sanitization: No sanitization or validation protocols for external inputs are documented.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:35 PM