story-mapping

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No security issues were detected. The skill is composed of informational Markdown files providing structured guidance on Jeff Patton's User Story Mapping methodology.
  • [NO_CODE]: The skill does not include any scripts (Python, JavaScript, Shell, etc.), binary files, or package dependency configurations (requirements.txt, package.json). All logic is delivered via prompts.
  • [EXTERNAL_DOWNLOADS]: No network activity, remote script execution, or external resource fetching was found in the skill content.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or attempts to access sensitive system file paths were found.
  • [PROMPT_INJECTION]: The skill uses the AskUserQuestion tool to ingest user-defined roles and goals. While this constitutes an indirect prompt injection surface, the skill is assessed as safe because it lacks any dangerous tools or capabilities (such as shell access, file writes, or network requests) that could be leveraged by an attacker. (Ingestion points: AskUserQuestion tool; Boundary markers: Absent; Capability inventory: None; Sanitization: Absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 12:06 PM
Security Audit — agent-trust-hub — story-mapping