developer-segmentation

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides strategic documentation and methodology for developer audience segmentation. It does not include executable code, shell scripts, or commands that interact with the system or network.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill does not perform network requests or access sensitive local files. External sources mentioned (SlashData, GitHub, RedMonk, Stack Overflow) are well-known developer industry sources used for data attribution and documentation purposes.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface for untrusted data (support tickets, sales notes, and user surveys). Evidence: Ingestion points identified in SKILL.md (Interview step 5) and references/sizing-sources.md; Boundary markers are absent; Capability inventory shows no file-write, network-ops, or subprocess calls; Sanitization logic is absent. The risk is assessed as safe as no dangerous capabilities are present in the skill instructions.\n- [PROMPT_INJECTION]: The instructions provide guidance on agent behavior as a strategist but do not attempt to bypass safety filters or override system-level instructions in a malicious way.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — developer-segmentation