variations
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, data exfiltration, or unauthorized command execution were detected. The skill's behavior is consistent with its stated purpose of assisting with UI/UX design variations.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it generates code and HTML files based on user-provided design descriptions. This risk is inherent to the skill's primary function of generating code from natural language and is mitigated by the instruction to use mock data.
- Ingestion points: User-provided descriptions of components, screens, or UX flows.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the generated output.
- Capability inventory: File system write access for creating temporary HTML artifacts and project route modification.
- Sanitization: There are no explicit instructions for the agent to sanitize or validate the user-supplied input before rendering it into code.
Audit Metadata