ux-audit
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill methodology involves processing untrusted content from external URLs and local source code to generate reports and remediation plans.\n
- Ingestion points: The agent reads data from
solution_urland files withinrepo_path(specified inSKILL.mdandtemplates/profile.yaml).\n - Boundary markers: The instructions include a 'Hydration-Probe' to check environment state but do not implement specific delimiters or warnings to ignore instructions embedded in audited pages.\n
- Capability inventory: The skill allows the agent to write files to an
audit/folder, execute shell diagnostics (grep,find), and use browser tools to interact with web content.\n - Sanitization: The skill lacks explicit logic to sanitize or escape data extracted from audited solutions before it is interpolated into audit reports.\n- [COMMAND_EXECUTION]: The skill methodology utilizes standard shell commands like
grepandfindto analyze code structures for accessibility issues and performance patterns (documented inchecks/A11Y-001.mdandchecks/PERF-002.md).\n- [EXTERNAL_DOWNLOADS]: The skill recommends executinglighthouseandvite-bundle-visualizervianpxto automate performance and asset measurements.lighthouseis an official tool from Google, a well-known service.
Audit Metadata