pm-business-model

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a shell script named check-update.sh located two levels above the skill's own directory to perform environment maintenance.
  • [COMMAND_EXECUTION]: Instructions for subagents include logic to locate a CLI utility (anysearch_cli.py) across several standard skill directory paths (e.g., ~/.claude/skills/, ~/.cursor/skills/) and execute it using Python to perform market research.
  • [INDIRECT_PROMPT_INJECTION]: The skill actively collects detailed user input through the AskUserQuestion tool for all nine elements of the Business Model Canvas. This data is then interpolated into a final markdown document (商业模式设计.md) written to the local file system. The skill relies on these inputs for its primary document-generation purpose without specific sanitization markers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 06:20 AM
Security Audit — agent-trust-hub — pm-business-model