icp-builder

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a legitimate workflow for product management and market research. All tool usages (Read, Write, WebSearch, Task) are consistent with the stated purpose of building an ICP.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the 'WebSearch' tool and parallel 'Task' subagents to gather market data. These operations are restricted to information gathering for research purposes and do not involve downloading or executing external scripts.
  • [DATA_EXFILTRATION]: No unauthorized data transmission was found. The skill writes the generated ICP profiles to local files (e.g., 'pmf/icp.md') and does not send sensitive user data to external servers.
  • [PROMPT_INJECTION]: The instructions are focused on guiding the user through the '5 Whys' and hypothesis formation. There are no patterns of prompt injection, such as attempts to bypass safety filters or override system instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 05:19 AM