asb-needs-stack
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its requirement to read and process external customer-related documentation.
- Ingestion points: The agent is instructed to read local files including
ideal-customer definitionfiles andcustomer-interview findingsduring the initialization phase (Phase A) to extract quotes and keystones. - Boundary markers: There are no defined boundary markers or specific instructions to treat the ingested file content as data rather than instructions.
- Capability inventory: The skill is capable of performing local file writes to
NEEDS-STACK.mdand invoking other environment-specific skills (e.g.,asb-rude-qa). - Sanitization: The instructions do not prescribe any validation, escaping, or filtering of the content read from the external files before it is processed by the model.
- [COMMAND_EXECUTION]: The skill contains instructions to programmatically invoke other environment-installed skills, such as
asb-rude-qa(Rude Q&A) for adversarial stack testing andasb-positioningfor downstream positioning tasks.
Audit Metadata