product-design-and-ux

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data such as user research, validated evidence, and product scope requirements. While this creates a potential surface for indirect prompt injection, the risk is minimal as the skill does not perform high-risk actions (like code execution or network requests) and explicitly instructs the agent to use synthetic fixtures and maintain traceability to authorized evidence. Evidence of mitigation includes instructions in references/usability-testing-and-privacy.md to use synthetic data and authorized observations only.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:57 PM
Security Audit — agent-trust-hub — product-design-and-ux