beautiful-gui-design

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes Node.js to run an internal audit script (scripts/gui_design_audit.mjs) and Python 3 to run a layout validation tool from a separate skill (layout-overflow-guard). These executions are part of the core functionality for auditing design specifications and are restricted to predefined file paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external design briefs (Markdown) and GUI specifications (JSON). This processing constitutes a potential attack surface for indirect instructions.
  • Ingestion points: The skill consumes design briefs and JSON specifications as defined in its IO contract.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are provided to the agent when processing these inputs.
  • Capability inventory: The agent has access to Bash, Read, Write, Edit, Grep, and Glob tools.
  • Sanitization: The skill provides a deterministic validation layer via gui_design_audit.mjs, which performs type and range checking on the JSON specification.
  • [EXTERNAL_DOWNLOADS]: The instructions recommend installing or syncing the layout-overflow-guard skill from the platform's skill catalog if it is not already present. This represents a functional dependency within the agent environment rather than a download from an untrusted remote server.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 07:43 PM
Security Audit — agent-trust-hub — beautiful-gui-design