ux-writing

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local JSON files, specifically extracting strings from the evidence.quotes[] array to use in generated UX copy. This creates a surface where instructions embedded in the user's corpus could be interpreted by the agent.
  • Ingestion points: The skill reads data from <corpus_root>/<slug>/jtbd.json as specified in SKILL.md.
  • Boundary markers: None identified. The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded within the corpus quotes.
  • Capability inventory: The skill generates text and initiates handoffs to other skills like respondent-panel.
  • Sanitization: No sanitization or validation logic is present to filter or escape the extracted strings before they are incorporated into the prompt context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:36 PM