ui-checkpoint
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration from
openspec/config.yamland user chat responses to determine workflow logic, such as whether to bypass human review or return to a build loop. Although no explicit boundary markers or sanitization methods are defined for these inputs, the process is designed as a manual checkpoint for the developer, which inherently limits the risk of automated prompt injection. - [COMMAND_EXECUTION]: The skill references the use of MCP tools to capture screenshots of build outputs for visual inspection. This functional use of external tools is restricted to the documented scope of UI/UX review and does not indicate unauthorized or malicious command execution.
Audit Metadata