ux-product-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for auditing external interfaces, creating a surface where malicious instructions embedded in a target website or app could attempt to influence the agent's behavior.
  • Ingestion points: The agent is instructed to audit a 'website, app, onboarding flow, or design' (SKILL.md).
  • Boundary markers: The instructions lack guidance on using delimiters or safety warnings to differentiate between the audit task and potential instructions contained within the audited content.
  • Capability inventory: The skill is composed entirely of markdown text and contains no executable scripts, tool definitions, or binary files.
  • Sanitization: There are no requirements or methods specified for sanitizing or validating the content extracted from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 01:18 PM
Security Audit — agent-trust-hub — ux-product-auditor