ui-to-vue
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
npxto execute theui-to-vue-converter@1.0.2package. While this is a vendor-provided tool, it involves downloading and running external code from the npm registry at runtime. - [EXTERNAL_DOWNLOADS]: The skill depends on the
ui-to-vue-converterpackage, which is retrieved from the public npm repository. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied screenshots, creating a surface for indirect prompt injection.
- Ingestion points: Design screenshots located in the user-specified input directory (defaulting to
./screenshots) as specified in theSKILL.mdinput section. - Boundary markers: No specific boundary markers or instructions are provided in the skill to isolate text or instructions that might be embedded within images from the AI's core task instructions.
- Capability inventory: The skill generates Vue 3 component source code, shared components, and router wiring, and writes these files to the local file system (e.g.,
./src). - Sanitization: The skill provides a manual 'Output Review Checklist' and explicitly warns users to 'Review generated Vue code before committing it,' serving as a human-in-the-loop sanitization step.
Audit Metadata