ui-design
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external task descriptions and representative data to generate user interface prototypes. This represents an attack surface where malicious instructions could be embedded in the design brief or fixture data processed by the agent.
- Ingestion points:
SKILL.mdandevals/evals.jsonindicate the agent ingests "supplied tasks", "briefs", and "realistic fixture content". - Boundary markers:
SKILL.mdincludes an explicit warning to the agent that theevals/directory is for maintenance and not to be injected into tasks. - Capability inventory: The agent performs file-writing (generating
index.html) and is instructed to usePythonandplaywright-clito verify designs during evaluation. - Sanitization: No explicit sanitization or validation of the input briefs is described.
- [DYNAMIC_EXECUTION]: The skill's primary function is to generate executable HTML, CSS, and JavaScript. The evaluation framework also suggests the use of browser automation tools (
playwright-cli) to verify the resulting designs. This is consistent with the skill's purpose for building and testing UI prototypes.
Audit Metadata