software-ux-research
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for analyzing untrusted external data, which is a known attack surface for indirect prompt injection.\n
- Ingestion points: Untrusted data enters the agent context through workflows described in
references/pain-point-extraction.md,references/review-mining-playbook.md, andreferences/feedback-tools-guide.md.\n - Boundary markers: The LLM prompt templates included in the skill (e.g., in
references/pain-point-extraction.md) do not use delimiters or defensive instructions to protect the agent from malicious input in the user data.\n - Capability inventory: The skill's capabilities are limited to network-read operations via
curl(inreferences/pain-point-extraction.mdandreferences/review-mining-playbook.md) and local file-append operations for logging (referenced inSKILL.md). It does not employ arbitrary shell execution or unsafe dynamic code interpretation.\n - Sanitization: There are no sanitization or validation steps mentioned for external content before it is processed by the agent.
Audit Metadata