scene-user-demand-research
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because its core workflow involves collecting and analyzing untrusted feedback from third-party sources.
- Ingestion points: The agent ingests data from external platforms through "public pages, permitted APIs, research datasets, or user-authorized exports" as specified in
SKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or protective headers to isolate untrusted external text when it is provided to the agent for synthesis or analysis.
- Capability inventory: The skill facilitates the collection, normalization, and synthesis of data into "opportunity cards" and product decisions.
- Sanitization: The research protocol does not include explicit instructions for the agent to sanitize or filter potential malicious instructions embedded within the feedback text.
- [EXTERNAL_DOWNLOADS]: The research protocol involves connecting to and fetching content from external web platforms and APIs.
- Evidence:
SKILL.mdandreferences/research-protocol.mddefine a workflow for mining reviews and forums, though they explicitly instruct the agent to respect access controls, login walls, and robots.txt restrictions.
Audit Metadata