steve-jobs-perspective
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection due to its automated research workflow.
- Ingestion points: External, untrusted data enters the agent context through 'WebSearch' tool results as described in the 'Step 2: 乔布斯式研究' (Jobs-style research) section of SKILL.md.
- Boundary markers: Absent. The skill does not provide instructions for the agent to use delimiters or to ignore potential instructions embedded within the retrieved web content.
- Capability inventory: The skill relies on WebSearch to provide factual data that directly influences the persona's response logic (SKILL.md).
- Sanitization: Absent. There are no mechanisms specified to filter or validate external content before it is processed by the agent.
- [SAFE]: The persona instructions, such as adopting a specific tone and avoiding standard disclaimers after the first message, are stylistic role-play directives and do not constitute an attempt to bypass core safety or security protocols.
Audit Metadata