ux-researcher

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data such as user interview transcripts and usability testing results, which creates a surface for indirect prompt injection.\n
  • Ingestion points: Research data collected in Phase 2 (interviews, usability testing, analytics review) as described in SKILL.md.\n
  • Boundary markers: Absent; no delimiters or "ignore embedded instructions" warnings are defined to isolate the research data from the agent's core instructions.\n
  • Capability inventory: The skill defines an output structure for writing markdown reports to a project-specific directory (.forgewright/ux-researcher/) but does not utilize high-risk tools like arbitrary code execution or network exfiltration.\n
  • Sanitization: Absent; the skill does not mention validating, escaping, or filtering the content of the research data it ingests.\n- [COMMAND_EXECUTION]: The skill employs dynamic context injection to include local project files at load time.\n
  • Evidence: !cat skills/_shared/protocols/ux-protocol.md 2>/dev/null || true in SKILL.md.\n
  • Evidence: !cat .production-grade.yaml 2>/dev/null || echo "No config — using defaults" in SKILL.md.\n
  • These shell commands target static paths for internal documentation and configuration and do not include user-controlled arguments, representing legitimate configuration loading in a development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 07:28 PM
Security Audit — agent-trust-hub — ux-researcher