think-five-whys

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied problem descriptions, creating a surface for indirect instructions. The absence of high-risk capabilities mitigates this risk.
  • Ingestion points: Untrusted user input enters the framework during the problem statement phase defined in SKILL.md (Step 2).
  • Boundary markers: The framework utilizes specific status flags ([single cause], [branch]) for output logic but does not define explicit delimiters to isolate the initial user input from its own instructions.
  • Capability inventory: Analysis of all skill files confirms no use of subprocesses, system commands, file system writes, or network requests.
  • Sanitization: There are no filters or validation steps defined for the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 PM
Security Audit — agent-trust-hub — think-five-whys