layout-audit

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract and process layout data from external project files, which creates a vector for instructions embedded in data to influence the agent.
  • Ingestion points: The skill uses uiux_extract_spacing to pull data from target files as described in SKILL.md.
  • Boundary markers: There are no instructions provided to the agent to treat the extracted data as untrusted or to ignore embedded natural language instructions.
  • Capability inventory: The skill uses specific analytical tools (uiux_extract_spacing, uiux_generate_spacing_scale) to audit data.
  • Sanitization: No sanitization or validation logic is defined to check the content of the extracted spacing values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:48 PM
Security Audit — agent-trust-hub — layout-audit