ui-design

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development commands, including linting, testing, and building the project, to ensure the quality and correctness of the generated UI code (SKILL.md, Step 5).
  • [EXTERNAL_DOWNLOADS]: The workflow incorporates external design references from 21st.dev, fetched via web search and screenshot capabilities to provide targeted component inspiration (SKILL.md, Step 3).
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its ingestion of external data from third-party websites during the inspiration phase.
  • Ingestion points: Web search results and screenshot data from 21st.dev (SKILL.md, Step 3).
  • Boundary markers: No specific delimiters or boundary markers are established to isolate external content from the agent's instructions.
  • Capability inventory: The skill allows the agent to write implementation code to the local filesystem and execute shell commands for build and validation (SKILL.md, Step 4 and 5).
  • Sanitization: No explicit sanitization or validation logic is defined for the content retrieved from external sources before it influences code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 07:14 PM
Security Audit — agent-trust-hub — ui-design