preventing-ui-slop
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The instructions provided in
SKILL.mddefine quality constraints for UI design and do not contain any patterns associated with prompt injection or safety bypasses. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external UI design requirements, which represents a potential ingestion surface for indirect instructions.
- Ingestion points: User prompts for UI creation, editing, and review as defined in
SKILL.mdandevals/evals.json. - Boundary markers: The skill uses a structured table of constraints ('Do not introduce these defaults') to guide agent responses.
- Capability inventory: The agent generates UI code and design copy; no high-risk capabilities like network access or shell execution are enabled by this skill.
- Sanitization: The guardrails specifically instruct the agent to remove redundant or fabricated content from the processed design tasks.
- [SAFE]: Maintenance scripts in the
scripts/directory perform integrity checks on the local package files. Thevalidate.pyscript usesyaml.safe_load()for frontmatter parsing andast.parse()for static syntax checking of Python files, avoiding dynamic execution of untrusted code.
Audit Metadata