skillcodex-browser-ui

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill requests access to suggest-shell to run build and development commands such as pnpm dev. While these are standard for UI development, they provide a vector for command execution within the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions depend on external reference files such as references/data-source.md and references/design-guidelines.md to drive UI generation.
  • Ingestion points: Content from references/data-source.md and references/design-guidelines.md is interpolated into the agent's task context for UI construction.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within these data sources.
  • Capability inventory: The skill uses suggest-shell to generate and run code based on the ingested data.
  • Sanitization: There is no mention of sanitizing or validating the contents of the reference files before processing.
  • [METADATA_POISONING]: The last_reviewed field in the YAML frontmatter is set to 2026-05-20, which is a future date. While not directly malicious, this is an inconsistency in the skill's metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:03 AM
Security Audit — agent-trust-hub — skillcodex-browser-ui