skills/alfred-lau/skills/implement-ui/Gen Agent Trust Hub

implement-ui

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions define a legitimate process for UI development. All operations are local to the repository, and no evidence of exfiltration, credential theft, or remote code execution was found.\n- [PROMPT_INJECTION]: The skill processes project-specific specification files through the 'Load contract' step. This ingestion of external data is a potential attack surface for indirect prompt injection, but the risk is minimized by the requirement to follow the design tokens and specifications faithfully, which limits the agent's autonomy and potential to execute injected commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 07:13 AM
Security Audit — agent-trust-hub — implement-ui