skills/h00mankind/workflow/variations/Gen Agent Trust Hub

variations

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, data exfiltration, or unauthorized command execution were detected. The skill's behavior is consistent with its stated purpose of assisting with UI/UX design variations.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it generates code and HTML files based on user-provided design descriptions. This risk is inherent to the skill's primary function of generating code from natural language and is mitigated by the instruction to use mock data.
  • Ingestion points: User-provided descriptions of components, screens, or UX flows.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the generated output.
  • Capability inventory: File system write access for creating temporary HTML artifacts and project route modification.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the user-supplied input before rendering it into code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:29 PM
Security Audit — agent-trust-hub — variations