ui-ux-pro-max
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: HIGHPERSISTENCEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [PERSISTENCE]: The
persist_design_systemfunction inscripts/design_system.pyis vulnerable to path traversal. It uses unsanitized user-controlled input from the--project-nameand--pagearguments to construct file system paths. Specifically, the transformationproject_name.lower().replace(' ', '-')does not filter or validate directory traversal sequences like../. Combined withPath.mkdir(parents=True, exist_ok=True), this allows the skill to create directories and write files to arbitrary locations on the user's filesystem, including sensitive areas like shell profiles (~/.bashrc) or SSH configurations. - [INDIRECT_PROMPT_INJECTION]: The skill implements an architecture described in
SKILL.mdwhere the agent is instructed to read and prioritize rules from locally written markdown files (design-system/MASTER.mdanddesign-system/pages/*.md). This creates a vulnerability surface for indirect prompt injection. - Ingestion points:
design-system/MASTER.mdanddesign-system/pages/[page-name].md(viaSKILL.mdinstructions). - Boundary markers: Absent. The instructions tell the agent to 'strictly follow' or 'prioritize' these rules without sanitization or isolation.
- Capability inventory: The skill possesses file-writing capabilities in
scripts/design_system.pyand file-reading capabilities via the agent's standard toolset (e.g.,cat,ls). - Sanitization: Absent. The content of the written files is derived from search results across local CSV data which, while local, are interpolated directly into markdown files that the agent is then told to obey as a source of truth.
- [PRIVILEGE_ESCALATION]:
SKILL.mdexplicitly provides instructions for users to executesudo apt installon Linux systems to install Python 3. While intended for environment setup, recommending the use ofsudofor tool installation increases the risk profile of the setup process.
Recommendations
- AI detected serious security threats
Audit Metadata