nielsen-heuristics
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust framework for heuristic evaluation with clear boundaries and documentation. The external references and tool integrations follow standard patterns.
- [COMMAND_EXECUTION]: The skill includes instructions for exporting findings to project management tools using the
linearandbd(Beads) CLIs. These commands are gated by a mandatory 'propose-then-confirm' step, ensuring no tasks are created without explicit user approval. The commands use standard arguments and do not involve suspicious network operations or sensitive file access. - [EXTERNAL_DOWNLOADS]: The skill references a mascot image (
assets/jakob-nielsen.png) and delegates HTML report generation to a separatetufte-reportskill. These are internal skill assets or legitimate cross-skill invocations for presentation purposes. - [DATA_EXFILTRATION]: No patterns of data exfiltration were detected. The skill accesses user-provided artifacts (screenshots, URLs, code) for the purpose of analysis as requested by the user. Network operations are limited to the intended functionality of browsing a target URL or interacting with project management APIs (Linear) via authorized CLIs.
- [PROMPT_INJECTION]: The skill instructions include 'honesty guards' and 'scope guards' designed to keep the AI focused on the formal rubric and prevent it from improvising findings or audits outside the Nielsen framework. There are no instructions to bypass safety filters or override system prompts.
Audit Metadata