user-research-cookiy

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as an installer or pointer for the full version of the user research assistant. It contains no executable code itself and follows expected patterns for a repository-based installation stub.
  • [EXTERNAL_DOWNLOADS]: The skill references and provides commands to install resources from the vendor's GitHub repository (cookiy-ai/user-research-skill). This is consistent with its stated purpose and the provided author context.
  • [PROMPT_INJECTION]: The skill description indicates it processes external data such as interview transcripts and user notes. This creates an ingestion surface for potential indirect prompt injection (Category 8), though this is a standard risk for research tools and is mitigated by the agent's core safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:10 AM
Security Audit — agent-trust-hub — user-research-cookiy