skills/ethan-rio/skills/ui-ux-pro-max/Gen Agent Trust Hub

ui-ux-pro-max

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a local reference library for design systems. It uses a Python-based search engine (BM25) to query local CSV files. No malicious patterns such as credential theft, data exfiltration, or unauthorized network activity were found.
  • [COMMAND_EXECUTION]: Shell commands are used strictly to invoke the skill's own local Python scripts. The scripts do not use dangerous functions like eval() or exec() on user-supplied input.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user queries to generate design systems, the risk is negligible. The queries are tokenized for rank-based search against local static data. When persisting results to the filesystem, the skill uses a safe_slug function that effectively prevents path traversal attacks by collapsing all non-alphanumeric characters (including separators like / and ..) into single dashes.
  • [EXTERNAL_DOWNLOADS]: Data files such as threejs.csv reference well-known and trusted CDN services (e.g., cdnjs.com) for library inclusion in user projects. These are informative guidelines for the developer and are not automated downloads or runtime dependencies of the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — ui-ux-pro-max