skills/rmyndharis/antigravity-skills/startup-business-analyst-financial-projections/Gen Agent Trust Hub
startup-business-analyst-financial-projections
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- PROMPT_INJECTION (LOW): The skill is vulnerable to Indirect Prompt Injection (Category 8) because it uses
WebSearchandWebFetchto gather external benchmarks while handling highly sensitive user data. - Ingestion points:
WebSearchresults,WebFetchcontent, and the localresources/implementation-playbook.mdfile. - Boundary markers: Absent. The instructions do not provide delimiters or specific guidelines for the agent to ignore instructions embedded in retrieved web content.
- Capability inventory: The skill allows
Bash,WebFetch,WebSearch, andWritetools. If an injection occurred via a malicious web page, these tools could be used to exfiltrate collected financial data. - Sanitization: No sanitization or validation of external content is specified in the instructions.
- DATA_EXFILTRATION (SAFE): The skill's primary purpose is to collect and analyze sensitive business data (MRR, Cash Balance, Burn Rate). While this creates a high-value target, no patterns of unauthorized exfiltration or hardcoded malicious destinations were detected. The data collection is consistent with the skill's stated purpose.
- COMMAND_EXECUTION (SAFE): Although the
Bashtool is permitted in the metadata, the skill instructions do not contain any hardcoded shell commands, scripts, or patterns of dynamic command generation. The risk is minimized as the tool appears to be for general agent environment interaction rather than specific automated execution.
Audit Metadata