customer-journey-map
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages project data locally, writing output to a specific 'docs/ux-research/maps/' directory, which is standard behavior for document-generating tools.
- [SAFE]: Interactions with external components are limited to internal agents ('persona-builder', 'renderer') and configuration schemas located within the plugin root.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface where user-provided descriptions of journey phases (Step 3) and product descriptions (Step 1.5) are captured from the agent context. No explicit boundary markers or sanitization logic are defined in the instructions before the data is written to 'map.json' or processed by the 'renderer.md' agent. This represents an inherent attack surface for indirect prompt injection, though it is consistent with the skill's intended functional purpose. Ingestion points include Step 1.5 and Step 3; capability inventory includes file-write and agent dispatch; boundary markers and sanitization are absent.
Audit Metadata