ux-discovery
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill manages a structured workflow that involves creating directories and writing multiple markdown files to the local file system within the
docs/discovery/path. - [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection (Category 8) by incorporating user-provided answers into subsequent agent prompts and documentation.
- Ingestion points: User answers collected during Stage 1 in
SKILL.md. - Boundary markers: Not explicitly defined for the interpolated user content.
- Capability inventory: File system operations and parallel sub-agent spawning via the
Tasktool as described inSKILL.md. - Sanitization: No sanitization or input validation for user-provided content is specified.
Audit Metadata