ui-ux-pro-max

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided project and page names and interpolates them into markdown documentation files. These files are then intended to be read by the agent to guide its behavior, creating a potential injection surface.\n
  • Ingestion points: User input enters the system via the --project-name and --page CLI arguments in scripts/search.py.\n
  • Boundary markers: Absent; the generated documentation files (MASTER.md and page-specific markdown files) do not include delimiters or instructions to ignore potentially malicious content embedded in the design rules.\n
  • Capability inventory: The script scripts/design_system.py performs file-write operations, creating directories and markdown files on the local file system.\n
  • Sanitization: Absent; input used in file headers is converted to lowercase and has spaces replaced by hyphens, but does not filter for embedded NL instructions or escape markdown characters.\n- [COMMAND_EXECUTION]: The Python utility scripts allow for directory traversal via unsanitized command-line arguments during the documentation generation process.\n
  • Evidence: In scripts/design_system.py, the project_slug and page parameters are used to construct file paths using Path joins without validating that they do not contain parent directory references (..) or absolute path characters.\n
  • Impact: While the script forces a .md extension on page files, the lack of sanitization allows the skill to write files to unintended directories within the agent's permission scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:05 PM
Security Audit — agent-trust-hub — ui-ux-pro-max