skills/m1nga/skills/thinking-partner/Gen Agent Trust Hub

thinking-partner

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation and configuration for agent behavior. It does not include executable scripts, binary files, or network-enabled tools.
  • [PROMPT_INJECTION]: The instructions are designed to improve the agent's reasoning process and do not contain patterns intended to bypass safety filters or override system constraints. The skill explicitly encourages 'accurate surface understanding' and requires evidence before adopting deep interpretations of user needs, which serves as a defensive measure against misinterpretation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted, potentially messy user input (dictated text, mixed languages) to help resolve decisions. While it lacks explicit delimiters or sanitization for this input, the framework's focus on separating 'what the user said' from 'what the evidence shows' reduces the risk of the agent blindly following instructions embedded within user data.
  • [COMMAND_EXECUTION]: Section 3 of SKILL.md suggests the agent should use available tools, files, and data to inform its thinking. However, the skill does not define or execute any dangerous commands itself; it relies on the execution environment's existing tool permissions and safety boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 AM
Security Audit — agent-trust-hub — thinking-partner