refactor-ui
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
run_commandtool to execute local TypeScript scripts (scripts/audit-ui.tsandscripts/check-contrast.ts) via the Bun runtime. These scripts perform deterministic static analysis of frontend code to identify UI anti-patterns and calculate WCAG contrast ratios. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted frontend source code (e.g., JSX, TSX, CSS) to perform audits and refactoring tasks. This creates a potential surface where malicious instructions embedded in the analyzed code could attempt to influence the agent's output.
- Ingestion points: User-provided file paths for UI components and templates.
- Boundary markers: The instructions mandate a specific report format using a severity table and require "proof" (binding rule + runtime path + deterministic fix) for each finding to ensure the agent ignores non-compliant data instructions.
- Capability inventory:
view_file,replace_file_content,write_to_file, andrun_command(limited to internal scripts). - Sanitization: Findings are derived from regex-based patterns in the audit script and mathematical contrast calculations, rather than dynamic execution of the ingested data.
Audit Metadata