goal-define
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed of static Markdown documents and templates defining a business analysis workflow. There are no executable scripts, shell commands, or dangerous network operations defined within the skill logic.
- [PROMPT_INJECTION]: Analysis of the instructions and templates revealed no attempts to override agent behavior, bypass safety filters, or extract system prompts. The skill uses professional, task-oriented language.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. The skill manages research evidence locally within the project workspace.
- [INDIRECT_PROMPT_INJECTION]: The skill defines ingestion points for external data via upstream documents (e.g., 04-painpoints.md) and web search results. This is a standard functional requirement for research-oriented skills. The risk is mitigated by the use of structured output templates (07-goals.md) and a formal research policy.
- [EXTERNAL_DOWNLOADS]: While the skill instructions permit the use of Web Search for research purposes, there are no automated downloads of executable scripts or unverifiable third-party packages.
Audit Metadata