jobs-to-be-done

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed of Markdown instructions and templates for conducting product management discovery. No malicious code or command execution patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to process external data such as customer interview notes and support tickets. While it lacks explicit boundary markers to delimit this data, the skill has no dangerous capabilities that could be exploited via injection.
  • Ingestion points: Processes user-provided interview notes and research documents (SKILL.md).
  • Boundary markers: Absent; the skill relies on standard LLM context processing.
  • Capability inventory: None; the skill contains no subprocess calls, file-write operations, or network access.
  • Sanitization: Absent; data is processed as natural language text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:55 PM
Security Audit — agent-trust-hub — jobs-to-be-done