ue-component-model

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes local project files like JavaScript and CSS to generate configuration. This ingestion of untrusted data represents an indirect prompt injection surface, where malicious content in source files could attempt to influence the agent. However, this interaction is necessary for the skill's legitimate developer-facing purpose.
  • Ingestion points: blocks/<name>/<name>.js, blocks/<name>/<name>.css, and root JSON configuration files.
  • Boundary markers: Absent.
  • Capability inventory: Create and edit local JSON configuration files.
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The reference materials include links to official Adobe JSON schemas (hosted on adobe.io), which are legitimate vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:35 AM
Security Audit — agent-trust-hub — ue-component-model