product-user-research

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits metadata poisoning through extreme redundancy. Eight reference files, including 'references/architecture-patterns.md', 'references/security-best-practices.md', and 'references/testing-strategies.md', each contain 150 repetitive sections. Each section repeats identical, generic engineering paragraphs and code snippets hundreds of times. This deceptive bloat misleads users about the skill's technical depth and appears intended to manipulate RAG-based context retrieval or overwhelm the agent's context window.
  • [PROMPT_INJECTION]: The research synthesis process described in 'SKILL.md' (Step 5) is susceptible to indirect prompt injection. (1) Ingestion points: Raw interview transcripts and survey data are ingested into the agent context in Step 5. (2) Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded instructions. (3) Capability inventory: The agent uses summarization and artifact generation capabilities to process this data. (4) Sanitization: Absent; no filtering or validation is performed on the ingested content, creating a risk that adversarial instructions in a transcript could be followed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:27 PM
Security Audit — agent-trust-hub — product-user-research