Back to skill

Security audit

Jtbd Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Jobs-To-Be-Done analysis skill, with no evidence of code execution, data access, persistence, or harmful behavior.

Install this if you want a framework for JTBD-style customer and product analysis. Be aware it may trigger on broad product-strategy phrasing, and the marketplace capability tags for crypto/purchases appear inconsistent with the actual text-only skill, so review permissions shown at install time if the platform presents any.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains multiple broad trigger phrases such as "user needs," "what problem," and "why do people buy," which can match many ordinary product or customer-analysis requests outside a narrowly intended JTBD context. This can cause the agent to invoke the skill unexpectedly, increasing prompt-surface area and creating routing/behavior hijacking risk even though the skill content itself is not overtly malicious.

Static analysis

No suspicious patterns detected.