better-interface

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant data ingestion surface that could be exploited to influence agent behavior through malicious instructions embedded in project files.
  • Ingestion points: In SKILL.md, Section 3 ("Recon before judgment") explicitly directs the agent to read untrusted project files including CONTRIBUTING.md, CODING_STANDARDS.md, AGENTS.md, CLAUDE.md, design-system documentation, and Storybook documentation.
  • Boundary markers: There are no instructions for the agent to use delimiters or ignore potential commands hidden within the text of these external files.
  • Capability inventory: The skill has access to the full repository content and is authorized to execute shell commands to verify findings.
  • Sanitization: No validation or sanitization protocols are mentioned for the external content being processed.
  • [COMMAND_EXECUTION]: The skill is designed to discover and run shell commands defined within the project's own environment.
  • Evidence: Section 9 ("Verify what can be verified") and Section 3 ("Recon before judgment") instruct the agent to identify framework-specific "preview or test commands" and "run the safe, relevant checks the project offers." While these are intended for quality assurance, they represent an execution path for scripts defined in an untrusted workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 01:54 PM
Security Audit — agent-trust-hub — better-interface