ux-audit

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill methodology involves processing untrusted content from external URLs and local source code to generate reports and remediation plans.\n
  • Ingestion points: The agent reads data from solution_url and files within repo_path (specified in SKILL.md and templates/profile.yaml).\n
  • Boundary markers: The instructions include a 'Hydration-Probe' to check environment state but do not implement specific delimiters or warnings to ignore instructions embedded in audited pages.\n
  • Capability inventory: The skill allows the agent to write files to an audit/ folder, execute shell diagnostics (grep, find), and use browser tools to interact with web content.\n
  • Sanitization: The skill lacks explicit logic to sanitize or escape data extracted from audited solutions before it is interpolated into audit reports.\n- [COMMAND_EXECUTION]: The skill methodology utilizes standard shell commands like grep and find to analyze code structures for accessibility issues and performance patterns (documented in checks/A11Y-001.md and checks/PERF-002.md).\n- [EXTERNAL_DOWNLOADS]: The skill recommends executing lighthouse and vite-bundle-visualizer via npx to automate performance and asset measurements. lighthouse is an official tool from Google, a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:48 PM
Security Audit — agent-trust-hub — ux-audit