asb-who-me

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to conduct a structured interview with the user. It uses psychological prompts (e.g., 'even-as-a-kid', 'pit-of-my-stomach dread') to help users document their characteristics in a local file named WHO-ME.md.
  • [DATA_EXPOSURE]: The skill manages a file named WHO-ME.md. This is a local file used for persistent state and memory within the skill's own defined workflow. There are no instructions or capabilities to send this data to external servers or non-whitelisted domains.
  • [COMMAND_EXECUTION]: The instructions mention an optional closing press that can be delegated to another skill (asb-rude-qa), but this is a call to a sibling agent skill, not an arbitrary shell command or remote code execution. If the skill is not present, it provides instructions to perform the task manually through conversation.
  • [PROMPT_INJECTION]: While the skill uses strong instructional language to maintain its persona as a 'stubborn' interviewer, these instructions are intended to ensure the quality of the self-discovery process (e.g., insisting on concrete episodes over labels). There are no patterns suggesting attempts to bypass underlying AI safety filters or exfiltrate system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 05:48 PM
Security Audit — agent-trust-hub — asb-who-me