asb-needs-stack

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its requirement to read and process external customer-related documentation.
  • Ingestion points: The agent is instructed to read local files including ideal-customer definition files and customer-interview findings during the initialization phase (Phase A) to extract quotes and keystones.
  • Boundary markers: There are no defined boundary markers or specific instructions to treat the ingested file content as data rather than instructions.
  • Capability inventory: The skill is capable of performing local file writes to NEEDS-STACK.md and invoking other environment-specific skills (e.g., asb-rude-qa).
  • Sanitization: The instructions do not prescribe any validation, escaping, or filtering of the content read from the external files before it is processed by the model.
  • [COMMAND_EXECUTION]: The skill contains instructions to programmatically invoke other environment-installed skills, such as asb-rude-qa (Rude Q&A) for adversarial stack testing and asb-positioning for downstream positioning tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:33 PM
Security Audit — agent-trust-hub — asb-needs-stack