beautiful-gui-design
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes Node.js to run an internal audit script (
scripts/gui_design_audit.mjs) and Python 3 to run a layout validation tool from a separate skill (layout-overflow-guard). These executions are part of the core functionality for auditing design specifications and are restricted to predefined file paths. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external design briefs (Markdown) and GUI specifications (JSON). This processing constitutes a potential attack surface for indirect instructions.
- Ingestion points: The skill consumes design briefs and JSON specifications as defined in its IO contract.
- Boundary markers: No specific delimiters or instructions to ignore embedded content are provided to the agent when processing these inputs.
- Capability inventory: The agent has access to
Bash,Read,Write,Edit,Grep, andGlobtools. - Sanitization: The skill provides a deterministic validation layer via
gui_design_audit.mjs, which performs type and range checking on the JSON specification. - [EXTERNAL_DOWNLOADS]: The instructions recommend installing or syncing the
layout-overflow-guardskill from the platform's skill catalog if it is not already present. This represents a functional dependency within the agent environment rather than a download from an untrusted remote server.
Audit Metadata