plan-uiux-unification
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository source code and external web content to perform its audit, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill performs
grepandgloboperations across codebase files (e.g.,.tsx,.jsx,.vue,.css) and usesFirecrawlto research design best practices from external websites. - Boundary markers: A strict 'Preservation Contract' is defined in
references/preservation-contract.md, which mandates that the agent must not fabricate data, remove features, or guess codebase facts, and requires all findings to be cited from verified file paths. - Capability inventory: The skill utilizes file system search tools (
grep,glob), network-based research tools (Firecrawl), and browser automation (Playwright) for visual verification. - Sanitization: While the skill enforces strict output guidelines and reasoning steps, it does not explicitly specify sanitization protocols for content ingested from the repository or the web before it is processed for report generation.
Audit Metadata