steve-jobs-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted data from the WebSearch tool during its research phase in SKILL.md (Step 2: 乔布斯式研究). * Ingestion points: Untrusted product reviews, technical analyses, and user feedback are fetched from external websites and incorporated into the model's context. * Boundary markers: The instructions do not define clear delimiters or explicit warnings to ignore instructions within the retrieved data, increasing the risk of the model obeying commands embedded in external web content. * Capability inventory: The skill's capabilities are limited to platform-provided search tools and natural language generation; it lacks file system access or non-whitelisted network capabilities. * Sanitization: There is no evidence of sanitization, escaping, or filtering of the retrieved web content before it is used to generate the persona's response.
  • [NO_CODE]: The skill package contains no executable code, scripts, or binaries. All files are documentation and instructional Markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — steve-jobs-perspective