107-ui-experience
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple project files to generate UX design directions and documentation.
- Ingestion points: Step 2 and Step 3 involve reading and loading context from
D01,D02,D05,D06, and.specflow/context/domain-knowledge.mdto feed into subsequent tool calls. - Boundary markers: The instructions do not require the use of delimiters (e.g., XML tags or triple quotes) or "ignore embedded instructions" warnings when passing the content of these files to the
@designeror@exploretools. - Capability inventory: The skill is authorized to write files to the disk (
.specflow/docs/D07-ui-experience.md) and can trigger other agent tools based on the analyzed data. - Sanitization: There is no evidence of sanitization, filtering, or validation of the content read from the Markdown files before it is interpolated into prompts for the LLM.
Audit Metadata