ux-plan-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data such as user context and prior findings to inform the creation of UX tasks.
- Ingestion points: Data enters through the 'supplied requirements, user context, and prior findings' referenced in the SKILL.md.
- Boundary markers: No explicit markers are used to separate user-provided context from the agent's instructions.
- Capability inventory: The skill is restricted to documentation and plan modification; it has no network access or command execution capabilities.
- Sanitization: No sanitization is performed on the ingested data.
- [NO_CODE]: The skill consists entirely of instructional markdown and does not include scripts, binaries, or automated installation of dependencies.
Audit Metadata