user-research

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown-based templates and instructional guides for user research (personas, journey maps, interview scripts). Analysis of all provided files shows no executable code, shell script components, or suspicious patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill's configuration permits the ingestion of web data via WebFetch and WebSearch tools. This creates a baseline surface for indirect prompt injection where external data could influence the agent's output. However, the skill lacks high-privilege tools (such as file writing, shell access, or credential access) required to exploit such an injection or perform data exfiltration. The behavior is limited to helping a user structure qualitative observations into templates.
  • Ingestion points: WebFetch and WebSearch tools enabled in SKILL.md frontmatter.
  • Boundary markers: The skill provides structured markdown templates (e.g., in rules/research-personas.md) that naturally compartmentalize data, though explicit delimiter markers for external content are not included.
  • Capability inventory: Agent capabilities are restricted to reading files (Read, Glob, Grep) and fetching web content; no write or execute capabilities are provided.
  • Sanitization: No sanitization logic or script-based filtering is present in the markdown-based distribution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — user-research