ux-audit
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including frontend code, component code, page URLs, and product requirements. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed content could influence the agent's actions, particularly during code modification tasks.
- Ingestion points: External data enters the agent context through the "Input Types" specified in
SKILL.md(Screenshots, Page URLs, Existing frontend/component code, Product requirements). - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore instructions embedded within the processed data.
- Capability inventory: The skill includes an "Implementation Mode" that allows the agent to modify code and perform implementation tasks. It also involves network-based reading of external URLs.
- Sanitization: There are no instructions for the agent to sanitize, escape, or validate external content before it is interpolated into the analysis or used for code generation.
Audit Metadata