Back to skill

Security audit

Jtbd Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Jobs-To-Be-Done analysis helper with no code execution, credential access, persistence, or data-moving behavior.

Reasonable to install if you want a JTBD/product-strategy assistant. Be aware it may trigger on some generic product questions, and do not treat the crypto or purchase metadata tags as evidence that this skill can safely handle money, wallets, or purchases.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The invocation description includes generic phrases such as "what problem" and "user needs," which are common in ordinary conversation and could match many unrelated requests. The file does not provide narrowing constraints or negative examples to clarify when this skill should activate versus when other analysis skills should be used.

Static analysis

No suspicious patterns detected.