ui-ux-pro-max

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface in its optional design system persistence feature, which creates local files based on user-supplied parameters.
  • Ingestion points: In scripts/search.py, user-supplied strings for the --project-name and --page arguments are passed to the persist_design_system function in scripts/design_system.py.
  • Boundary markers: The output generated by the skill consists of standard Markdown files; however, user-influenced project and page titles are not enclosed in delimiters or sanitized to prevent them from potentially altering the intended file path structure.
  • Capability inventory: The skill scripts (scripts/design_system.py) utilize os.path.join, Path.mkdir, and standard file write operations, providing an interface for local file system modifications.
  • Sanitization: The project_name and page variables undergo minimal sanitization (conversion to lowercase and space-to-hyphen replacement). The logic does not validate against directory traversal sequences (e.g., ../), allowing a user to influence the directory where design files are created.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:37 AM
Security Audit — agent-trust-hub — ui-ux-pro-max