pmf-crossing-the-chasm

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation, business strategy frameworks, and historical case studies (Salesforce, AI Coding Assistants). No executable scripts (Python, JavaScript, shell) are included.
  • [SAFE]: All external links point to official documentation, primary sources, or the vendor's own informational pages (deciqai.com). There is no evidence of obfuscation, remote code execution, or data exfiltration.
  • [PROMPT_INJECTION]: The skill uses natural instructional language for 'Coach mode' and 'Engine mode', but does not contain patterns intended to bypass AI safety filters or override core system instructions. The instructions are scoped to the business analysis domain.
  • [DATA_EXFILTRATION]: There are no commands or instructions that access sensitive file paths (e.g., .ssh, .env) or perform network operations. The analysis is performed on user-provided business data.
  • [COMMAND_EXECUTION]: The skill does not use shell commands, subprocesses, or dynamic execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — pmf-crossing-the-chasm