steve-jobs-perspective

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection due to its automated research workflow.
  • Ingestion points: External, untrusted data enters the agent context through 'WebSearch' tool results as described in the 'Step 2: 乔布斯式研究' (Jobs-style research) section of SKILL.md.
  • Boundary markers: Absent. The skill does not provide instructions for the agent to use delimiters or to ignore potential instructions embedded within the retrieved web content.
  • Capability inventory: The skill relies on WebSearch to provide factual data that directly influences the persona's response logic (SKILL.md).
  • Sanitization: Absent. There are no mechanisms specified to filter or validate external content before it is processed by the agent.
  • [SAFE]: The persona instructions, such as adopting a specific tone and avoiding standard disclaimers after the first message, are stylistic role-play directives and do not constitute an attempt to bypass core safety or security protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 04:09 PM
Security Audit — agent-trust-hub — steve-jobs-perspective