uiux-ia-user-flows

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project data which creates a surface for indirect prompt injection. \n
  • Ingestion points: The procedure in SKILL.md involves reading external "product model" and "research implications" files to establish the design context. \n
  • Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore or delimit potentially malicious instructions within the ingested project data. \n
  • Capability inventory: The agent is authorized to write and update multiple project documentation files, including 03-information-architecture.md and handoffs/structure.md. No network access, arbitrary command execution, or other high-risk capabilities are present. \n
  • Sanitization: The skill lacks validation or sanitization routines for the data it processes, relying on the agent to interpret the input content directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:29 PM
Security Audit — agent-trust-hub — uiux-ia-user-flows