ui-to-vue
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The instructions rely on the installation and execution of the
ui-to-vue-converterpackage from the public NPM registry, which is a third-party community resource. - [COMMAND_EXECUTION]: The skill provides commands for shell execution via
npxor globally installed binaries. These tools perform automated file system operations (reading screenshots and writing generated Vue components) and communicate with external APIs. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided visual data (screenshots) and processes it to generate executable code, which presents a theoretical surface for malicious content within images to influence the code output.
- Ingestion points: Local design images and screenshots provided in the user-specified input directory.
- Boundary markers: No specific delimiters or safety warnings for the image processing stage are identified.
- Capability inventory: Executes the
ui-to-vue-converterCLI tool, reads local file directories, and writes generated JavaScript/Vue files to the./srcdirectory. - Sanitization: The skill explicitly instructs users to review all generated components, mock data, and assets before committing them to a repository.
Audit Metadata