ux-designer
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is configured to analyze untrusted external data, which creates a potential vector for indirect instructions.\n
- Ingestion points: Processes data from URLs and local file paths passed as arguments through tools like WebFetch and Read (SKILL.md).\n
- Boundary markers: The instructions lack explicit delimiters or specific warnings to the agent to disregard embedded instructions within the fetched data.\n
- Capability inventory: The skill includes Bash in its allowed tools list, which allows for shell command execution that could be exploited if malicious instructions in external data are processed.\n
- Sanitization: No evidence of content validation or sanitization was found in the analysis of the skill's instructions or logic.
Audit Metadata