ux-writing
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local JSON files, specifically extracting strings from the
evidence.quotes[]array to use in generated UX copy. This creates a surface where instructions embedded in the user's corpus could be interpreted by the agent. - Ingestion points: The skill reads data from
<corpus_root>/<slug>/jtbd.jsonas specified inSKILL.md. - Boundary markers: None identified. The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded within the corpus quotes.
- Capability inventory: The skill generates text and initiates handoffs to other skills like
respondent-panel. - Sanitization: No sanitization or validation logic is present to filter or escape the extracted strings before they are incorporated into the prompt context.
Audit Metadata