ui-design
Fail
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to modify the user's application source code by injecting a remote JavaScript file (
https://ui.sh/ui-picker.js) into core layout files, such asindex.html,RootLayout.tsx,app.vue, andapp.blade.php. This facilitates the persistent execution of remote code within the application's context. - [COMMAND_EXECUTION]: The skill utilizes the
npx @tailwindcss/cli canonicalizecommand to optimize CSS class strings. This involves running an external CLI tool that may download and execute code locally during the build or development process. - [EXTERNAL_DOWNLOADS]: The skill fetches assets and scripts from external domains, specifically
ui.shandassets.ui.sh. It also references third-party font services like Google Fonts and Fontshare for typography implementation. - [PROMPT_INJECTION]: The skill processes user-supplied images (screenshots, mockups) to generate code scaffolds in
markup-from-image.md, creating a surface for indirect prompt injection. - Ingestion points:
markup-from-image.mdaccepts screenshots and mockups for code generation. - Boundary markers: There are no explicit instructions for the agent to ignore or sanitize instructions that may be visually embedded in the processed images.
- Capability inventory: The agent has the capability to write the resulting code directly to files in the repository and execute shell commands.
- Sanitization: The skill lacks validation or filtering for text content extracted from processed images.
Recommendations
- AI detected serious security threats
Audit Metadata