business-identity-scope
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference materials do not contain malicious commands, credentials, or obfuscated content.
- [SAFE]: The skill references established research from well-known organizations including Harvard Business Review, McKinsey & Company, and NYU Stern. These references are used for methodological context and do not involve remote code execution or suspicious downloads.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external business and market data, which constitutes an untrusted ingestion point.
- Ingestion points: The agent analyzes company economics, management claims, and market data (SKILL.md, references/business-definition.md).
- Boundary markers: The methodology explicitly requires the identification of 'disconfirming evidence' and 'alternative frames,' which reduces the risk of the agent following instructions embedded in the analyzed data (references/evidence-standard.md).
- Capability inventory: The skill does not possess or request tools for command execution, file system modification, or network requests.
- Sanitization: There is no automated sanitization of input, but the lack of dangerous capabilities mitigates the associated risk.
Audit Metadata