icp-builder

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs web searches and utilizes subagents to research customer personas. It also contains a reference to the author's public GitHub repository for attribution and feedback.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided product descriptions and customer pain points. While these inputs are used to generate search queries and subagent tasks, the structured nature of the interaction and the specific task scope minimize the risk of indirect injection. No dangerous command execution is tied to this external data ingestion.
  • [COMMAND_EXECUTION]: The skill uses the Task tool to launch subagents for research. These subagents operate under defined prompts for market analysis and do not involve shell command execution or system-level modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 10:08 AM
Security Audit — agent-trust-hub — icp-builder