cto-advisor
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOWPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION] (INFO): The skill references the execution of local scripts ('scripts/tech_debt_analyzer.py', 'scripts/team_scaling_calculator.py') to perform technical debt and scaling analysis. While these files were not provided for analysis, their described use cases are consistent with the skill's management-oriented purpose.
- [INDIRECT_PROMPT_INJECTION] (LOW): The skill's core functions include analyzing external inputs like architecture specifications and vendor responses, which presents an indirect injection surface. 1. Ingestion points: Architecture decision records and technology evaluation frameworks in references/architecture_decision_records.md and references/technology_evaluation_framework.md. 2. Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the templates. 3. Capability inventory: Capability to execute local analysis scripts as defined in SKILL.md. 4. Sanitization: No sanitization or validation protocols for external inputs are documented.
Audit Metadata