jobs-to-be-done

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate processing of external, untrusted data like interview transcripts or customer feedback, which is a vector for indirect prompt injection.\n
  • Ingestion points: Analysis of user-supplied interview notes and timelines in SKILL.md and innovation-process.md.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for processing user data.\n
  • Capability inventory: The skill lacks tool calls, shell commands, or network operations, which significantly mitigates the risk.\n
  • Sanitization: No sanitization or filtering of external input is described.\n- [SAFE]: No executable code, scripts, or sensitive file access patterns were found. The skill is purely informational.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:07 PM
Security Audit — agent-trust-hub — jobs-to-be-done