ui-audit
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands, specifically
ripgrep(rg) andfind, to perform static analysis on the project's source code. These commands are used to detect patterns such as missing error boundaries, lack of loading skeletons, and incorrect use of React hooks. This is the intended primary purpose of the tool and does not involve execution of untrusted external code. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads and processes source code files which may contain untrusted content. This surface is inherent to its function as a code auditor. The evidence chain for this surface includes: 1) Ingestion points: local source files (.tsx, .ts, .jsx, .js, .css); 2) Boundary markers: absent; 3) Capability inventory:
rg,find, and file read operations; 4) Sanitization: absent. The skill includes internal self-check instructions to ensure findings are grounded in evidence to mitigate this risk. - [SAFE]: No malicious patterns, data exfiltration attempts, or unauthorized network operations were detected. All external references are to reputable developer documentation and industry-standard tools.
Audit Metadata