app-idea-research
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill functions as a structured set of instructions for market research and validation. Its operations, including web-based research and local file generation, are entirely consistent with its stated purpose. No malicious patterns or security vulnerabilities were identified in the markdown instructions or reference playbooks.- [NO_CODE]: The skill package consists exclusively of markdown documentation and instructional templates. It does not include any Python scripts, Node.js packages, or binary executables, which minimizes the technical attack surface and eliminates risks associated with dynamic code execution.- [PROMPT_INJECTION]: The skill uses a specific instructional persona ("brutally honest skeptic") to guide the agent's evaluation process. While it processes data from external sources like Reddit and XDA-Developers, this indirect prompt injection surface is used solely for synthesis and reporting. The skill lacks high-privilege capabilities that could be abused via injected instructions.- [DATA_EXFILTRATION]: All network activity is directed toward well-known public research domains (e.g., Google Trends, Reddit, App Store). No evidence was found of the skill accessing sensitive local files (such as SSH keys or environment variables) or exfiltrating private data.
Audit Metadata