skillcodex-browser-ui
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill requests access to
suggest-shellto run build and development commands such aspnpm dev. While these are standard for UI development, they provide a vector for command execution within the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The skill instructions depend on external reference files such as
references/data-source.mdandreferences/design-guidelines.mdto drive UI generation. - Ingestion points: Content from
references/data-source.mdandreferences/design-guidelines.mdis interpolated into the agent's task context for UI construction. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within these data sources.
- Capability inventory: The skill uses
suggest-shellto generate and run code based on the ingested data. - Sanitization: There is no mention of sanitizing or validating the contents of the reference files before processing.
- [METADATA_POISONING]: The
last_reviewedfield in the YAML frontmatter is set to2026-05-20, which is a future date. While not directly malicious, this is an inconsistency in the skill's metadata.
Audit Metadata