plan-uiux-unification

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository source code and external web content to perform its audit, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill performs grep and glob operations across codebase files (e.g., .tsx, .jsx, .vue, .css) and uses Firecrawl to research design best practices from external websites.
  • Boundary markers: A strict 'Preservation Contract' is defined in references/preservation-contract.md, which mandates that the agent must not fabricate data, remove features, or guess codebase facts, and requires all findings to be cited from verified file paths.
  • Capability inventory: The skill utilizes file system search tools (grep, glob), network-based research tools (Firecrawl), and browser automation (Playwright) for visual verification.
  • Sanitization: While the skill enforces strict output guidelines and reasoning steps, it does not explicitly specify sanitization protocols for content ingested from the repository or the web before it is processed for report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:42 PM
Security Audit — agent-trust-hub — plan-uiux-unification