value-story-framework
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as a set of text-based guidelines for a business process. It contains no executable instructions, network requests, or sensitive file access.
- [NO_CODE]: The skill is composed entirely of Markdown documentation and does not include scripts, binaries, or shell execution blocks.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs (discovery insights).
- Ingestion points: The skill body mentions translating "discovery insights" into narratives.
- Boundary markers: No specific delimiters or safety warnings for external input are provided.
- Capability inventory: The skill does not possess any tools, network capabilities, or file system access.
- Sanitization: No explicit sanitization or validation logic is defined.
Audit Metadata