personal-ui-taste

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed to provide design guidelines and interaction patterns for frontend development. A thorough analysis of the instructions, metadata, and protocols reveals no malicious code, unauthorized network operations, or attempts to access sensitive system files.
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates an 'Evolution Protocol' documented in evolution.md, which instructs the agent to update the skill's own core instruction files (SKILL.md, patterns.md) based on user feedback and project interactions. This mechanism represents an attack surface where external input could potentially be persisted into the skill's logic. However, the protocol includes defensive instructions such as requiring explicit confirmation, distilling feedback into generic UI language rather than transcribing raw logs, and using specific metadata tags (Confirmed/Candidate) to distinguish between vetted and unvetted instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:02 PM
Security Audit — agent-trust-hub — personal-ui-taste