lean-ux-canvas
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external text-based data such as product briefs (PRDs), stakeholder memos, and user research to populate the canvas. Ingestion points: SKILL.md (Step 0) and Questions 1-4. Boundary markers: None explicitly defined. Capability inventory: None; the skill is limited to interactive text output and does not utilize tools for command execution, network requests, or file system modifications. Sanitization: None performed. The risk is assessed as safe due to the lack of actionable capabilities for an attacker to exploit.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected. The skill's external references point to legitimate documentation for the Lean UX framework, and its instructions align with its stated purpose of facilitation.
Audit Metadata