ui-ux-pro-max

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: HIGHPERSISTENCEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [PERSISTENCE]: The persist_design_system function in scripts/design_system.py is vulnerable to path traversal. It uses unsanitized user-controlled input from the --project-name and --page arguments to construct file system paths. Specifically, the transformation project_name.lower().replace(' ', '-') does not filter or validate directory traversal sequences like ../. Combined with Path.mkdir(parents=True, exist_ok=True), this allows the skill to create directories and write files to arbitrary locations on the user's filesystem, including sensitive areas like shell profiles (~/.bashrc) or SSH configurations.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an architecture described in SKILL.md where the agent is instructed to read and prioritize rules from locally written markdown files (design-system/MASTER.md and design-system/pages/*.md). This creates a vulnerability surface for indirect prompt injection.
  • Ingestion points: design-system/MASTER.md and design-system/pages/[page-name].md (via SKILL.md instructions).
  • Boundary markers: Absent. The instructions tell the agent to 'strictly follow' or 'prioritize' these rules without sanitization or isolation.
  • Capability inventory: The skill possesses file-writing capabilities in scripts/design_system.py and file-reading capabilities via the agent's standard toolset (e.g., cat, ls).
  • Sanitization: Absent. The content of the written files is derived from search results across local CSV data which, while local, are interpolated directly into markdown files that the agent is then told to obey as a source of truth.
  • [PRIVILEGE_ESCALATION]: SKILL.md explicitly provides instructions for users to execute sudo apt install on Linux systems to install Python 3. While intended for environment setup, recommending the use of sudo for tool installation increases the risk profile of the setup process.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — ui-ux-pro-max