nmt-craft-go-to-market

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as Notion exports, interview notes, and existing marketing copy. \n
  • Ingestion points: Material provided during the intake process and scraped customer reviews (SKILL.md).\n
  • Boundary markers: The instructions mandate an 'input-as-hypothesis' gate and a 'validation debt' framing that requires the agent to verify all provided claims rather than treating them as established facts.\n
  • Capability inventory: The skill uses network calls and background subagents for research.\n
  • Sanitization: Relies on reasoning-based risk assessment for all external inputs.\n- [DYNAMIC_EXECUTION]: The skill includes instructions to perform a version check by executing a shell command (curl). This command reads a local version file and contacts the official methodology domain (nextmovetheory.com) to compare versions. This is a transparent administrative function.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Basic telemetry, including the skill name and version number, is transmitted to the vendor's domain during update checks. This behavior is consistent with the stated purpose of keeping the skill updated with the latest methodology canon.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 09:30 AM
Security Audit — agent-trust-hub — nmt-craft-go-to-market