user-researcher

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [SAFE]: Analysis of the skill instructions and metadata found no evidence of malicious intent, obfuscation, or unauthorized access to sensitive information.
  • [NO_CODE]: The skill contains no scripts, binaries, or automated tasks, relying entirely on the agent's interpretation of markdown instructions.
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze external data sources, creating a surface for indirect prompt injection.
  • Ingestion points: Evidence synthesis from interviews, support logs, and sales calls (SKILL.md, examples/README.md).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands in external data are provided.
  • Capability inventory: The skill does not define or include any executable scripts, tools, or subprocess calls.
  • Sanitization: No sanitization or validation logic is specified for the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 11:47 AM
Security Audit — agent-trust-hub — user-researcher