skills/neurofoo/agent-skills/jtbd/Gen Agent Trust Hub

jtbd

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input to generate product analysis reports, which presents a surface for indirect prompt injection.
  • Ingestion points: User input is ingested via the $ARGUMENTS placeholder in SKILL.md, commands/jobs.md, and commands/jtbd.md.
  • Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the processed data.
  • Capability inventory: The skill has no active capabilities; it does not use network, filesystem, or shell tools. Its operations are restricted to text generation within the AI's conversation context.
  • Sanitization: There is no evidence of input validation or sanitization, though the lack of dangerous tools limits the risk to output manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:31 PM
Security Audit — agent-trust-hub — jtbd