ux-friction-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided UI designs, HTML, and journey maps, which creates a potential surface for instructions embedded within that data to influence the agent.
  • Ingestion points: Processes interface designs, user paths, and HTML snippets provided by the user for audit (SKILL.md).
  • Boundary markers: The skill lacks explicit delimiters or instructions to treat provided UX data as non-executable text, which could lead to accidental obedience of embedded commands.
  • Capability inventory: The skill is granted Read, Write, Edit, and WebFetch permissions (SKILL.md frontmatter).
  • Sanitization: There are no defined mechanisms for sanitizing or filtering instructions that might be present in the user-provided design documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:59 PM
Security Audit — agent-trust-hub — ux-friction-analyzer