frontend-ui-workflow
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns such as hardcoded credentials, remote code execution, or persistence mechanisms were detected.
- [SAFE]: The skill implements a strict 'Scope Boundary' that prevents the agent from modifying backend files, API endpoints, or infrastructure without explicit user permission.
- [SAFE]: Design system fidelity is enforced through mandatory 'Style Extraction' and 'Layout Extraction' steps, preventing the introduction of arbitrary or malicious styles.
- [SAFE]: The skill processes untrusted user requirements and existing codebase source, which creates a surface for potential indirect prompt injection. This risk is mitigated by the workflow's requirement to produce structured intermediate artifacts (layout.md, experience.md, implementation-plan.md) which act as functional boundaries and structural validation steps before any code generation occurs.
- [SAFE]: All references and instructions are self-contained within the skill's directory structure, and no external downloads or remote script executions were found.
Audit Metadata