interview-script

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-supplied arguments and documents such as personas or research briefs to tailor the generated interview script. While this introduces a surface for indirect prompt injection, the skill does not utilize any dangerous tools, file system writes, or network requests, significantly limiting the risk.
  • Ingestion points: Instructions refer to $ARGUMENTS and user-uploaded files like personas and product briefs.
  • Boundary markers: None explicitly defined in the template instructions.
  • Capability inventory: No execution capabilities (shell, subprocess, network) or tool invocations are present in the skill.
  • Sanitization: No input sanitization is performed on the provided context.
  • [EXTERNAL_DOWNLOADS]: The skill references external articles on productcompass.pm. These links point to the author's own educational content regarding user interviews and product discovery, representing standard vendor-provided documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:02 PM
Security Audit — agent-trust-hub — interview-script