ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided project and page names and interpolates them into markdown documentation files. These files are then intended to be read by the agent to guide its behavior, creating a potential injection surface.\n
- Ingestion points: User input enters the system via the
--project-nameand--pageCLI arguments inscripts/search.py.\n - Boundary markers: Absent; the generated documentation files (
MASTER.mdand page-specific markdown files) do not include delimiters or instructions to ignore potentially malicious content embedded in the design rules.\n - Capability inventory: The script
scripts/design_system.pyperforms file-write operations, creating directories and markdown files on the local file system.\n - Sanitization: Absent; input used in file headers is converted to lowercase and has spaces replaced by hyphens, but does not filter for embedded NL instructions or escape markdown characters.\n- [COMMAND_EXECUTION]: The Python utility scripts allow for directory traversal via unsanitized command-line arguments during the documentation generation process.\n
- Evidence: In
scripts/design_system.py, theproject_slugandpageparameters are used to construct file paths usingPathjoins without validating that they do not contain parent directory references (..) or absolute path characters.\n - Impact: While the script forces a
.mdextension on page files, the lack of sanitization allows the skill to write files to unintended directories within the agent's permission scope.
Audit Metadata