ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses local Python scripts to process internal data files (CSV) and generate design system documentation. It does not perform any network operations or access sensitive system files.
- [COMMAND_EXECUTION]: The skill instructions guide the agent to execute specific Python scripts located within the skill's directory. These scripts use standard libraries and perform search/aggregation tasks on internal data without exposing arbitrary command injection surfaces.
- [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive paths were found. The skill includes a 'persistence' feature that writes generated design systems to a local 'design-system/' directory, which is transparently documented and benign.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied search queries, the input is tokenized and used for a BM25 keyword search against a static database. The output consists of design guidelines and code snippets that are safe for the agent to present to the user.
- [REMOTE_CODE_EXECUTION]: The skill does not download external packages or execute code from remote sources.
Audit Metadata