living-ui-modify
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user requests and historical instructions stored in
reference/requirements.mdto guide its code modification tasks. - Ingestion points:
reference/requirements.md, project logs, and user-provided instruction strings. - Boundary markers: None specified for separating external data from system instructions.
- Capability inventory: Modifies application source code and server-side JavaScript logic; utilizes platform-specific tools for environment booting and validation.
- Sanitization: Relies on built-in platform validation gates (
living_ui_notify_ready,living_ui_walk_verify) to verify changes in a disposable environment before promotion. - [DYNAMIC_EXECUTION]: The skill generates and modifies server-side JavaScript hooks and database migrations intended for execution by the PocketBase backend. This activity is restricted to the application's workspace and is the primary function of the skill.
Audit Metadata