audit-ux

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches research guidelines and interaction principles from well-known industry sources including Nielsen Norman Group (nngroup.com), Intuit Content Design (intuit.com), and Laws of UX (lawsofux.com) using the Firecrawl MCP. These operations are consistent with the skill's stated purpose of providing research-driven evaluations.
  • [DATA_EXFILTRATION]: Performs local analysis of application code to identify UX patterns, such as searching for loading states, error handling markers, and hardcoded strings. This data is used solely for context in generating the UX audit report and is not sent to unauthorized external endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external web sources and the analyzed source code. While this represents a theoretical attack surface, the risk is mitigated by the skill's focus on reputable industry domains and its primary function as a research tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 06:53 PM
Security Audit — agent-trust-hub — audit-ux