brainstorm-frameworks

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions focus on applying brainstorming frameworks like SCAMPER and Six Thinking Hats. It does not contain any phrases designed to bypass safety filters, override system prompts, or reveal internal instructions. The use of structured templates with clear placeholders helps prevent instructions from being misinterpreted.
  • [DATA_EXFILTRATION]: There are no network operations, API calls, or commands that access sensitive environment variables or local files. The skill operates exclusively within the AI's instructional context and does not attempt to send data to external servers.
  • [REMOTE_CODE_EXECUTION]: The skill contains no executable scripts, shell commands, or binary files. It consists entirely of Markdown guidance, YAML/Markdown templates, and JSON schemas. No patterns involving the execution of remote or dynamically generated code were identified.
  • [NO_CODE]: This is a non-executable, purely instructional skill. It provides the AI agent with theoretical knowledge and structured prompts to improve its ideation capabilities without requiring any system-level access or tool execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided themes for brainstorming.
  • Ingestion points: User requests are processed via the {{USER_REQUEST}} placeholder in the templates/theme-clarifier.md file.
  • Boundary markers: The skill utilizes structured YAML blocks to encapsulate user data, providing clear separation between instructions and input data.
  • Capability inventory: The skill has no capabilities to execute commands, write files, or access the network, making the risk of exploitation through injection non-existent.
  • Sanitization: While no active sanitization is performed on input text, the lack of executable capabilities mitigates the associated risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 07:27 PM
Security Audit — agent-trust-hub — brainstorm-frameworks