think-theory-of-constraints
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists exclusively of instructional text and templates. There is no executable code, no script generation, and no reliance on external software packages or binary files.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-supplied data regarding system flows and organizational problems. This creates a surface for indirect prompt injection. However, because the skill defines no tool usage, network access, or file system permissions, there is no technical path to escalate an injection into a functional exploit. The analysis identifies this ingestion surface as a characteristic of the skill's purpose rather than a vulnerability.
- [EXTERNAL_DOWNLOADS]: The skill references the vendor's official GitHub repository (
github.com/product-on-purpose/thinking-framework-skills) for documentation and attribution. These are plain-text references to legitimate vendor resources and do not involve automated execution or risky remote code patterns.
Audit Metadata