ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a local reference library for design systems. It uses a Python-based search engine (BM25) to query local CSV files. No malicious patterns such as credential theft, data exfiltration, or unauthorized network activity were found.
- [COMMAND_EXECUTION]: Shell commands are used strictly to invoke the skill's own local Python scripts. The scripts do not use dangerous functions like
eval()orexec()on user-supplied input. - [INDIRECT_PROMPT_INJECTION]: While the skill ingests user queries to generate design systems, the risk is negligible. The queries are tokenized for rank-based search against local static data. When persisting results to the filesystem, the skill uses a
safe_slugfunction that effectively prevents path traversal attacks by collapsing all non-alphanumeric characters (including separators like/and..) into single dashes. - [EXTERNAL_DOWNLOADS]: Data files such as
threejs.csvreference well-known and trusted CDN services (e.g., cdnjs.com) for library inclusion in user projects. These are informative guidelines for the developer and are not automated downloads or runtime dependencies of the skill itself.
Audit Metadata