kmcp-dev-ui-spec
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses instructional constraints to define the agent's persona and focus, which is standard behavior for specialized agent skills. No attempts to bypass safety filters, jailbreak, or extract system prompts were found.
- [DATA_EXFILTRATION]: No sensitive file access or network exfiltration patterns were detected. References to
localhost:3300and internal project directories likesrc/ui/are consistent with a local development environment and design workflow. - [COMMAND_EXECUTION]: The skill mentions project-specific build commands like
npm run ui:buildin the context of documentation and workflow instructions, but it does not instruct the agent to execute them autonomously or via unsafe methods. - [SAFE]: The content is purely instructional, providing design guidelines, tokens, and accessibility rules. It does not contain obfuscated code, remote scripts, or persistence mechanisms.
Audit Metadata