new-screen

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses python3 to execute local scripts (project-system.py and contrast.py) within the skill's internal directory structure (.claude/skills/ordinary-interfaces/scripts/). These scripts are used for setup and accessibility verification as part of the intended UI workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user input via the $ARGUMENTS variable, which is interpolated into the text instructions to indicate the component being built.\n
  • Ingestion points: $ARGUMENTS in SKILL.md.\n
  • Boundary markers: None identified.\n
  • Capability inventory: The skill has access to filesystem tools (Bash, Read, Glob, Grep) and local script execution.\n
  • Sanitization: No explicit validation or sanitization of the user input is performed prior to interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 10:30 AM
Security Audit — agent-trust-hub — new-screen