ui-design
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard Unix utilities (
rg,find,xargs,git) to scan the codebase for UI and accessibility defects as part of its audit functionality. These commands are scoped to the project files and are used for static analysis. - [EXTERNAL_DOWNLOADS]: Fetches placeholder assets (avatars, logos, screenshots) from
https://assets.ui.sh. This is a purpose-specific service used to provide realistic UI mockups during the design process. - [INDIRECT_PROMPT_INJECTION]: As an audit tool, the skill is designed to ingest and analyze untrusted source code from the user's repository. It includes mitigations such as specific 'ignore' markers (
ui-audit-ignore:) and detailed instructions for the agent to verify findings at specific file and line locations before acting, reducing the risk of accidental obedience to instructions embedded in analyzed data. - [SAFE]: The skill demonstrates best practices for AI agent extensions, including strict 'load contracts' to prevent unauthorized scope creep, clear separation of concerns between modes (Audit, Build, Direction), and reliance on established industry tools like
axe-coreand@tailwindcss/cli.
Audit Metadata