preventing-ui-slop

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The instructions provided in SKILL.md define quality constraints for UI design and do not contain any patterns associated with prompt injection or safety bypasses.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external UI design requirements, which represents a potential ingestion surface for indirect instructions.
  • Ingestion points: User prompts for UI creation, editing, and review as defined in SKILL.md and evals/evals.json.
  • Boundary markers: The skill uses a structured table of constraints ('Do not introduce these defaults') to guide agent responses.
  • Capability inventory: The agent generates UI code and design copy; no high-risk capabilities like network access or shell execution are enabled by this skill.
  • Sanitization: The guardrails specifically instruct the agent to remove redundant or fabricated content from the processed design tasks.
  • [SAFE]: Maintenance scripts in the scripts/ directory perform integrity checks on the local package files. The validate.py script uses yaml.safe_load() for frontmatter parsing and ast.parse() for static syntax checking of Python files, avoiding dynamic execution of untrusted code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:40 AM
Security Audit — agent-trust-hub — preventing-ui-slop