pm-business-model
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a shell script named
check-update.shlocated two levels above the skill's own directory to perform environment maintenance. - [COMMAND_EXECUTION]: Instructions for subagents include logic to locate a CLI utility (
anysearch_cli.py) across several standard skill directory paths (e.g.,~/.claude/skills/,~/.cursor/skills/) and execute it using Python to perform market research. - [INDIRECT_PROMPT_INJECTION]: The skill actively collects detailed user input through the
AskUserQuestiontool for all nine elements of the Business Model Canvas. This data is then interpolated into a final markdown document (商业模式设计.md) written to the local file system. The skill relies on these inputs for its primary document-generation purpose without specific sanitization markers.
Audit Metadata