daily-ui-inspiration-capture

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script scripts/check-ui-inspiration-duplicates.mjs to perform deduplication checks on inspiration manifests. It also uses Git commands such as git status and git add -f to manage the article assets within the workspace.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its ingestion of data from external sources and local files.
  • Ingestion points: Data captured via the browser from external landing pages (Framer, Dribbble) and content read from previously generated local manifest.json files.
  • Boundary markers: Absent. The skill does not instruct the agent to use delimiters or ignore instructions that may be embedded in the captured design assets or metadata.
  • Capability inventory: Execution of local scripts, Git repository management, and filesystem write access.
  • Sanitization: Absent. Captured content is interpolated directly into the inspiration articles and manifests without explicit filtering or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — daily-ui-inspiration-capture