107-ui-experience

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple project files to generate UX design directions and documentation.
  • Ingestion points: Step 2 and Step 3 involve reading and loading context from D01, D02, D05, D06, and .specflow/context/domain-knowledge.md to feed into subsequent tool calls.
  • Boundary markers: The instructions do not require the use of delimiters (e.g., XML tags or triple quotes) or "ignore embedded instructions" warnings when passing the content of these files to the @designer or @explore tools.
  • Capability inventory: The skill is authorized to write files to the disk (.specflow/docs/D07-ui-experience.md) and can trigger other agent tools based on the analyzed data.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content read from the Markdown files before it is interpolated into prompts for the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:51 PM
Security Audit — agent-trust-hub — 107-ui-experience