ux-review
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided design files and project configuration documents as context for its review logic without using boundary markers.
- Ingestion points: The skill reads file paths passed via arguments in Phase 1 and supplementary files such as project.yaml, technical-preferences.md, and GDDs in Phase 2.
- Boundary markers: Absent. There are no delimiters or instructions to ignore embedded instructions within the processed data, which could allow a malicious design file to influence the review verdict.
- Capability inventory: The skill is limited to Read, Glob, and Grep tools. It lacks capabilities for network access, file writing, or command execution, which mitigates the impact of potential injection to text-based manipulation.
- Sanitization: Absent. Data from external files is interpolated into the model context without filtering or escaping.
Audit Metadata