ux-brief

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources to generate design briefs.
  • Ingestion points: The skill processes evaluation findings and decisions from supplied documents and files located at .jimmy/work/design-evaluation.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions in the ingested data.
  • Capability inventory: The skill writes the generated brief to the file system at .jimmy/work/design-brief.md.
  • Sanitization: No validation or sanitization of the input data is performed before it is incorporated into the output file.
  • [NO_CODE]: The skill consists entirely of markdown instructions and meta-documentation, with no executable scripts, binaries, or configuration files provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:14 PM
Security Audit — agent-trust-hub — ux-brief