ux
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown and configuration metadata. No executable code, scripts, or remote dependencies are included, and no sensitive data access or network exfiltration patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to analyze user-facing products and content, which is an ingestion point for untrusted data. While this presents a surface for indirect prompt injection, it is consistent with the skill's intended purpose and carries no associated high-risk capabilities. * Ingestion points: SKILL.md directs the agent to review various user-facing components like screens, APIs, and messages. * Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' directives for the data being analyzed. * Capability inventory: The skill does not define any scripts, subprocess calls, or file-system write operations. * Sanitization: No explicit sanitization or filtering logic is prescribed for the analyzed inputs.
Audit Metadata