ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates locally using a collection of CSV data files and Python scripts to provide design recommendations. No network activity or external data fetching (other than standard documentation URLs for well-known services) was detected.
- [COMMAND_EXECUTION]: The skill relies on the local execution of Python scripts (
search.py,core.py,design_system.py) to process user queries and retrieve design guidelines. These scripts are invoked via the CLI and interact solely with the provided local data files. The instructions also guide the user through the installation of Python 3 using standard system package managers (brew, apt, winget) if it is not already present. - [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it ingests user-provided keywords through the
search.pyCLI tool. This data is then used to query internal CSV databases using a BM25 ranking algorithm. The resulting design guidelines are presented back to the agent for synthesis. This is a low-risk surface given the restricted nature of the output (UI/UX guidelines) and the basic sanitization (tokenization) performed by the search engine.
Audit Metadata