ljg-invest

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted external data provided by the user.
  • Ingestion points: The skill explicitly triggers on external content such as pitch decks, meeting notes, founder interviews, and entrepreneur conversation records provided by the user.
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard instructions embedded within the provided data.
  • Capability inventory: The skill utilizes a 'Write' tool to save generated reports to the user's local file system at ~/Documents/notes/.
  • Sanitization: The instructions do not include steps to sanitize or validate the external input before it is incorporated into the analysis and written to disk.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 04:24 PM