cali-product-job-to-be-done
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no scripts, binaries, or executable content. It consists exclusively of markdown documentation and instructional prompt templates.
- [DATA_EXPOSURE]: External links point to the author's official blog on Substack (calirenato82.substack.com). These links are provided for attribution and educational reference; they target a well-known platform and represent no risk of data exfiltration or credential theft.
- [PROMPT_INJECTION]: The skill processes untrusted user input by interpolating it into predefined prompt templates (e.g.,
{{Purpose}},[fill in]). This creates a surface for indirect prompt injection. However, the skill implements boundary markers in its more complex prompts (using XML-style tags like<segment>and<situational factors and variables>) to help the agent distinguish between instructions and data. As the skill provides no dangerous tools or capabilities, this implementation follows standard prompt engineering practices.
Audit Metadata