user-researcher
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: Analysis of the skill instructions and metadata found no evidence of malicious intent, obfuscation, or unauthorized access to sensitive information.
- [NO_CODE]: The skill contains no scripts, binaries, or automated tasks, relying entirely on the agent's interpretation of markdown instructions.
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external data sources, creating a surface for indirect prompt injection.
- Ingestion points: Evidence synthesis from interviews, support logs, and sales calls (SKILL.md, examples/README.md).
- Boundary markers: No specific delimiters or instructions to ignore embedded commands in external data are provided.
- Capability inventory: The skill does not define or include any executable scripts, tools, or subprocess calls.
- Sanitization: No sanitization or validation logic is specified for the ingested content.
Audit Metadata