software-ux-research

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for analyzing untrusted external data, which is a known attack surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent context through workflows described in references/pain-point-extraction.md, references/review-mining-playbook.md, and references/feedback-tools-guide.md.\n
  • Boundary markers: The LLM prompt templates included in the skill (e.g., in references/pain-point-extraction.md) do not use delimiters or defensive instructions to protect the agent from malicious input in the user data.\n
  • Capability inventory: The skill's capabilities are limited to network-read operations via curl (in references/pain-point-extraction.md and references/review-mining-playbook.md) and local file-append operations for logging (referenced in SKILL.md). It does not employ arbitrary shell execution or unsafe dynamic code interpretation.\n
  • Sanitization: There are no sanitization or validation steps mentioned for external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — software-ux-research