layout-audit
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract and process layout data from external project files, which creates a vector for instructions embedded in data to influence the agent.
- Ingestion points: The skill uses
uiux_extract_spacingto pull data from target files as described in SKILL.md. - Boundary markers: There are no instructions provided to the agent to treat the extracted data as untrusted or to ignore embedded natural language instructions.
- Capability inventory: The skill uses specific analytical tools (
uiux_extract_spacing,uiux_generate_spacing_scale) to audit data. - Sanitization: No sanitization or validation logic is defined to check the content of the extracted spacing values.
Audit Metadata