skills/mblode/agent-skills/ui-design/Gen Agent Trust Hub

ui-design

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard Unix utilities (rg, find, xargs, git) to scan the codebase for UI and accessibility defects as part of its audit functionality. These commands are scoped to the project files and are used for static analysis.
  • [EXTERNAL_DOWNLOADS]: Fetches placeholder assets (avatars, logos, screenshots) from https://assets.ui.sh. This is a purpose-specific service used to provide realistic UI mockups during the design process.
  • [INDIRECT_PROMPT_INJECTION]: As an audit tool, the skill is designed to ingest and analyze untrusted source code from the user's repository. It includes mitigations such as specific 'ignore' markers (ui-audit-ignore:) and detailed instructions for the agent to verify findings at specific file and line locations before acting, reducing the risk of accidental obedience to instructions embedded in analyzed data.
  • [SAFE]: The skill demonstrates best practices for AI agent extensions, including strict 'load contracts' to prevent unauthorized scope creep, clear separation of concerns between modes (Audit, Build, Direction), and reliance on established industry tools like axe-core and @tailwindcss/cli.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 10:03 PM
Security Audit — agent-trust-hub — ui-design