ljg-invest
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted external data provided by the user.
- Ingestion points: The skill explicitly triggers on external content such as pitch decks, meeting notes, founder interviews, and entrepreneur conversation records provided by the user.
- Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard instructions embedded within the provided data.
- Capability inventory: The skill utilizes a 'Write' tool to save generated reports to the user's local file system at
~/Documents/notes/. - Sanitization: The instructions do not include steps to sanitize or validate the external input before it is incorporated into the analysis and written to disk.
Audit Metadata