journey-map-builder
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted research notes and transcripts. 1. Ingestion points: Research notes, transcripts, or described experiences provided by the user in SKILL.md. 2. Boundary markers: None present to delimit external data or instruct the agent to ignore embedded commands. 3. Capability inventory: Ability to create artifacts and structured specifications on a Figma Design canvas. 4. Sanitization: No evidence of data validation or filtering for ingested content. An attacker could embed instructions in research notes to influence the resulting map or agent behavior.
Audit Metadata