think-affinity-mapping

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and documentation for performing the KJ method (affinity mapping). It does not contain any executable scripts, network requests, or attempts to access sensitive system files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data (such as user research notes or support tickets). While it lacks the capabilities (no tools or shell access) to be exploited by malicious content within that data, it does not specify boundary markers to delimit untrusted input from instructions.
  • Ingestion points: Raw notes, observations, quotes, or data points processed in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: None; the skill uses no tools and has no script execution or network capabilities.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 PM
Security Audit — agent-trust-hub — think-affinity-mapping