skills/microsoft/hve-core/ux-coaching/Gen Agent Trust Hub

ux-coaching

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • External Documentation References: The skill links to official documentation from well-known sources, including Microsoft's engineering playbook and the UK Government (GOV.UK) service manual. These references are used solely for grounding the coaching methodology and do not involve executable code.
  • Session State Management: The skill maintains local state in the .copilot-tracking directory to allow users to resume coaching sessions. The instructions include specific constraints to exclude personal identifiers and limit file access to the designated project directory.
  • Input Sanitization Instructions: There is a clear security directive for the agent to treat all user-supplied content (such as transcripts or documents) as data rather than instructions. This is an effective measure to mitigate potential indirect prompt injection attacks where malicious commands might be hidden in data the agent processes.
  • Vendor-Aligned Infrastructure: As a Microsoft-authored skill, it utilizes the vendor's own engineering guidance and internal tracking patterns for session persistence, representing expected and standard functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:39 PM
Security Audit — agent-trust-hub — ux-coaching