skills/ztemerbekov/next-move-theory-canon-and-skills/nmt-craft-value-proposition/Gen Agent Trust Hub
nmt-craft-value-proposition
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (
catandcurl) at the end of its workflow to read a local version file and check for updates from the vendor's server. - [EXTERNAL_DOWNLOADS]: Initiates a network request to
nextmovetheory.comto verify the current version of the skill. This is a standard vendor-provided resource for maintenance. - [PROMPT_INJECTION]: Uses prescriptive instructions such as "Producer contract (binding)" and employs adversarial reviewer personas for internal self-critique. These are task-specific constraints designed for output quality rather than safety bypasses.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits vulnerability to indirect injection as it ingests untrusted data from user-provided files (e.g., Notion exports, strategy docs) in stage S0.
- Ingestion points: Stage S0 (Intake) reads local files and external market research results.
- Boundary markers: The skill uses an "Input-as-hypothesis gate" and explicitly tags user-provided data as hypotheses rather than facts.
- Capability inventory: The skill has access to subagent creation and shell command execution (
curl). - Sanitization: No explicit sanitization or delimiter wrapping for external content is specified beyond the logical treatment of input as "hypotheses."
Audit Metadata