ux-flows
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the application's local start command as part of its orchestration logic to ensure the environment is ready for testing.
- [PROMPT_INJECTION]: The skill processes external data from project files and codebase structures, creating an indirect prompt injection surface.
- Ingestion points: Reads flow definitions from e2e/flows/*.md and surveys the codebase for routing patterns.
- Boundary markers: No explicit delimiters or instructions are used to distinguish project data from agent instructions.
- Capability inventory: Executes project-specific shell commands and invokes external skills.
- Sanitization: No explicit validation or sanitization of ingested project content is performed.
Audit Metadata