user-research-cookiy
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as an installer or pointer for the full version of the user research assistant. It contains no executable code itself and follows expected patterns for a repository-based installation stub.
- [EXTERNAL_DOWNLOADS]: The skill references and provides commands to install resources from the vendor's GitHub repository (cookiy-ai/user-research-skill). This is consistent with its stated purpose and the provided author context.
- [PROMPT_INJECTION]: The skill description indicates it processes external data such as interview transcripts and user notes. This creates an ingestion surface for potential indirect prompt injection (Category 8), though this is a standard risk for research tools and is mitigated by the agent's core safety protocols.
Audit Metadata