ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute a local Python script (search.py) to query its internal database of design rules. The script is bundled with the skill package and does not call any external or unverified binaries.
- [DATA_EXFILTRATION]: Analysis of all Python scripts (core.py, search.py, design_system.py) confirms that no network-related modules such as requests, socket, or urllib are used. The skill does not attempt to transmit any information to remote servers.
- [PROMPT_INJECTION]: The skill body and its extensive data files were scanned for injection markers, role-play attempts, and instructions to override system constraints. No such patterns were found; the content consists strictly of technical UI/UX guidelines.
- [SAFE]: The skill implements a 'safe_slug' function using regular expressions to sanitize project and page names. This ensures that when the tool persists design system files to the local filesystem, it is protected against path traversal vulnerabilities.
- [EXTERNAL_DOWNLOADS]: The data files contain URLs for official documentation (e.g., angular.dev, nextjs.org) and well-known CDNs (e.g., cdnjs for Three.js). These are included as reference material for the user and are not used by the skill to fetch or execute remote code at runtime.
Audit Metadata