define-jtbd-canvas

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions and templates for product management analysis. It lacks any active components, such as scripts or tool calls, that could perform unauthorized actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data (user research and interview notes) to populate a JTBD canvas. However, the risk is negligible as the skill has no dangerous capabilities to exploit. 1. Ingestion points: User-provided research data and interview notes mentioned in instructions and evaluation fixtures. 2. Boundary markers: The skill does not define specific delimiters for untrusted data. 3. Capability inventory: None. The skill only generates text output within the agent conversation. 4. Sanitization: No sanitization or validation of the input data is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:21 AM
Security Audit — agent-trust-hub — define-jtbd-canvas