field
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves analyzing external research data (transcripts, surveys, feedback), which constitutes an inherent surface for indirect prompt injection. Malicious instructions embedded in processed data could potentially bias research findings or synthesis artifacts.
- Ingestion points: External research data, feedback from
Voice, and behavioral signals fromTraceare processed across multiple files includingSKILL.mdandreference/analysis-and-synthesis.md. - Boundary markers: The skill relies on structured templates and instructions for researchers to maintain objectivity but does not implement specific technical markers for data isolation in subagent prompts.
- Capability inventory: The skill is restricted to generating research documentation and triggering subagents for design generation; it is explicitly forbidden from generating implementation code.
- Sanitization: The instructions require PII anonymization, human verification of thematic coding, and adherence to strict data governance standards (SOC 2 Type II, GDPR).
Audit Metadata