user-research
Audited by ZeroLeaks on Apr 15, 2026
**Executive Summary** SKILL.md is clear, well-structured, and fully reviewable — it's a straightforward informational reference on user research methods with no tool invocations, code execution, or external data fetches. It stays clean on instruction/data boundaries and does not push the agent to treat user-supplied or external content as trusted instructions. The tested scenarios did not show material prompt-injection risk or skill-induced worsening of downstream behavior. Confidence is low, however, because behavior analysis was not run, meaning there is no empirical validation of how loading this skill actually changes downstream agent behavior compared to a no-skill baseline; finite testing and the absence of that comparison limit what can be conclusively claimed.
This skill is a purely informational reference for planning, conducting, and synthesizing user research. It contains no tool invocations, no code execution, no external fetches, no hidden behavior, and no authority claims. All behavior is fully described in the markdown.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.