ui-ux
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is composed entirely of markdown instructions and design process frameworks. It does not include any scripts, commands, or network operations.
- [NO_CODE]: There is no code or executable content within the skill, eliminating the risk of command injection, remote code execution, or persistence mechanisms.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing external data such as requirements and feedback. Ingestion points: User-provided PRDs and feedback (Phases 1, 2, 10). Boundary markers: Absent. Capability inventory: None (no subprocess calls, file-writes, or network operations). Sanitization: Absent. The lack of tool-execution or file-modification capabilities renders this risk negligible.
Audit Metadata