think-five-whys
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied problem descriptions, creating a surface for indirect instructions. The absence of high-risk capabilities mitigates this risk.
- Ingestion points: Untrusted user input enters the framework during the problem statement phase defined in
SKILL.md(Step 2). - Boundary markers: The framework utilizes specific status flags (
[single cause],[branch]) for output logic but does not define explicit delimiters to isolate the initial user input from its own instructions. - Capability inventory: Analysis of all skill files confirms no use of subprocesses, system commands, file system writes, or network requests.
- Sanitization: There are no filters or validation steps defined for the input data.
Audit Metadata