business-identity-scope

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference materials do not contain malicious commands, credentials, or obfuscated content.
  • [SAFE]: The skill references established research from well-known organizations including Harvard Business Review, McKinsey & Company, and NYU Stern. These references are used for methodological context and do not involve remote code execution or suspicious downloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external business and market data, which constitutes an untrusted ingestion point.
  • Ingestion points: The agent analyzes company economics, management claims, and market data (SKILL.md, references/business-definition.md).
  • Boundary markers: The methodology explicitly requires the identification of 'disconfirming evidence' and 'alternative frames,' which reduces the risk of the agent following instructions embedded in the analyzed data (references/evidence-standard.md).
  • Capability inventory: The skill does not possess or request tools for command execution, file system modification, or network requests.
  • Sanitization: There is no automated sanitization of input, but the lack of dangerous capabilities mitigates the associated risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 01:32 PM
Security Audit — agent-trust-hub — business-identity-scope