discovery-process

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a high-level workflow orchestration tool designed for product discovery processes. It guides the user through various phases such as problem framing, research planning, and synthesis using established frameworks (e.g., Teresa Torres, Marty Cagan).
  • [REMOTE_CODE_EXECUTION]: No patterns for remote code execution, such as curl-to-bash or package installation from unknown sources, were found.
  • [DATA_EXFILTRATION]: No network operations or sensitive file access patterns were identified. The skill operates within the agent's context using provided project data.
  • [PROMPT_INJECTION]: The instructions do not contain markers attempting to override safety guidelines or bypass AI restrictions.
  • [OBFUSCATION]: No Base64, zero-width characters, homoglyphs, or other encoding techniques were used to hide content.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied hypotheses and research notes (untrusted data). However, it lacks dangerous capabilities like shell command execution or network exfiltration, making the ingestion surface benign in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:38 PM
Security Audit — agent-trust-hub — discovery-process