refactor-ui

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the run_command tool to execute local TypeScript scripts (scripts/audit-ui.ts and scripts/check-contrast.ts) via the Bun runtime. These scripts perform deterministic static analysis of frontend code to identify UI anti-patterns and calculate WCAG contrast ratios.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted frontend source code (e.g., JSX, TSX, CSS) to perform audits and refactoring tasks. This creates a potential surface where malicious instructions embedded in the analyzed code could attempt to influence the agent's output.
  • Ingestion points: User-provided file paths for UI components and templates.
  • Boundary markers: The instructions mandate a specific report format using a severity table and require "proof" (binding rule + runtime path + deterministic fix) for each finding to ensure the agent ignores non-compliant data instructions.
  • Capability inventory: view_file, replace_file_content, write_to_file, and run_command (limited to internal scripts).
  • Sanitization: Findings are derived from regex-based patterns in the audit script and mathematical contrast calculations, rather than dynamic execution of the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — refactor-ui