pick-ui-library

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions require the agent to analyze the project's 'package.json' file to verify existing dependencies before making recommendations. This creates a surface for indirect prompt injection where a malicious configuration file could attempt to influence agent behavior. However, the logic is constrained to a hardcoded whitelist of libraries, significantly mitigating this risk.
  • Ingestion points: 'package.json' (SKILL.md)
  • Boundary markers: Absent
  • Capability inventory: The agent is directed to perform library installation and code wiring, involving shell command execution and file writing.
  • Sanitization: Recommendations are limited to a curated internal list.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to 'install/wire it up' when a library is selected. This involves the execution of package managers (e.g., npm or yarn) and file system modifications. This behavior is the primary intended purpose of the skill and aligns with developer-tooling workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — pick-ui-library