kmcp-dev-ui-spec

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses instructional constraints to define the agent's persona and focus, which is standard behavior for specialized agent skills. No attempts to bypass safety filters, jailbreak, or extract system prompts were found.
  • [DATA_EXFILTRATION]: No sensitive file access or network exfiltration patterns were detected. References to localhost:3300 and internal project directories like src/ui/ are consistent with a local development environment and design workflow.
  • [COMMAND_EXECUTION]: The skill mentions project-specific build commands like npm run ui:build in the context of documentation and workflow instructions, but it does not instruct the agent to execute them autonomously or via unsafe methods.
  • [SAFE]: The content is purely instructional, providing design guidelines, tokens, and accessibility rules. It does not contain obfuscated code, remote scripts, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 07:39 AM
Security Audit — agent-trust-hub — kmcp-dev-ui-spec