layers-observed-behaviour

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown text and YAML metadata. It does not include any scripts (Python, Node.js, Shell), configuration files, or executable binaries.
  • [SAFE]: The content is restricted to user research methodology (JTBD interviews, contextual inquiry, pattern synthesis). It does not request access to sensitive file paths, credentials, or administrative privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a workflow for processing external data such as user interviews, support tickets, and analytics. While this constitutes a data ingestion surface where external content could potentially contain malicious instructions, the skill does not define any capabilities (such as tool usage, file system writing, or network communication) that could be exploited by such an injection.
  • Ingestion points: Research material, support tickets, and interview transcripts processed in the 'Synthesise' mode.
  • Boundary markers: None explicitly defined.
  • Capability inventory: No tool usage, network operations, or shell commands are defined in the skill metadata or body.
  • Sanitization: None specified for external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:08 AM
Security Audit — agent-trust-hub — layers-observed-behaviour