108-ui-page-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a structured workflow for generating UI design specifications and mockups. It utilizes internal agent tools like
@designeror@exploreto research and generate layout directions. It does not execute arbitrary shell commands or access sensitive system credentials. - [INDIRECT_PROMPT_INJECTION]: The skill reads project documentation files (D01, D06, D07, domain-knowledge.md) to gather context. While this creates a surface for indirect prompt injection from those files, the skill's actions are restricted to file writes within a specific documentation directory. Notably, it includes a mandatory disclaimer comment in the generated HTML mockup to prevent downstream LLMs from misinterpreting the design as production code, reducing the risk of the agent's own output becoming a vector for further issues.
Audit Metadata