ux-product-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for auditing external interfaces, creating a surface where malicious instructions embedded in a target website or app could attempt to influence the agent's behavior.
- Ingestion points: The agent is instructed to audit a 'website, app, onboarding flow, or design' (SKILL.md).
- Boundary markers: The instructions lack guidance on using delimiters or safety warnings to differentiate between the audit task and potential instructions contained within the audited content.
- Capability inventory: The skill is composed entirely of markdown text and contains no executable scripts, tool definitions, or binary files.
- Sanitization: There are no requirements or methods specified for sanitizing or validating the content extracted from external sources.
Audit Metadata