usability-review

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and act upon data from external sources that are not under the developer's control.
  • Ingestion points: SKILL.md indicates the skill processes content from live URLs, HTML/CSS/JS code, and user-provided screenshots.
  • Boundary markers: The instructions do not define specific delimiters or security constraints to distinguish between the agent's instructions and the content of the audited UI components.
  • Capability inventory: The agent uses the platform's /browse tool and has the potential to write modifications to the user's UI source files when in 'Redesign Mode' (as specified in SKILL.md).
  • Sanitization: There are no instructions for sanitizing or filtering the external code or website data before it is analyzed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 05:44 PM
Security Audit — agent-trust-hub — usability-review