design-thinking

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown content and theoretical frameworks. No executable scripts, binaries, or configuration files that could trigger system actions are present.
  • [EXTERNAL_DOWNLOADS]: The skill links to external resources for academic and professional reference. These domains (hbr.org, designkit.org, mckinsey.com, anthropic.com, deciqai.com) are well-known and reputable. No automated remote code execution or script piping patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a coaching interaction in SKILL.md that ingests user-provided information about their products and users.
  • Ingestion points: Step 3 and 4 of the 'Coaching Novices' section where the agent asks for the user's case and observation history.
  • Boundary markers: The skill uses [WAIT] tags to delimit interaction steps.
  • Capability inventory: The skill has no access to sensitive tools, subprocesses, file-writing capabilities, or network operations.
  • Sanitization: No specific content filtering or sanitization is implemented for the text-based coaching feedback.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — design-thinking