daily-ui-inspiration-capture
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external websites to generate UI inspiration bundles and AI prompts. This creates a surface for indirect prompt injection where malicious content on a visited page could attempt to subvert the agent's instructions. Ingestion points: External web content accessed via the browser tool. Boundary markers: None identified in the instructions for sanitizing or isolating web content. Capability inventory: Local file system writes, execution of a local Node.js script, and git operations. Sanitization: No explicit sanitization of text extracted from websites is described.
- [COMMAND_EXECUTION]: The skill executes local commands including
git status,git add, and a Node.js scriptnode scripts/check-ui-inspiration-duplicates.mjs. These are used for project management and data validation as part of the intended workflow.
Audit Metadata