interface-review

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches guidelines from Vercel's official GitHub repository (https://raw.githubusercontent.com/vercel-labs/web-interface-guidelines/main/command.md). This is a well-known service and considered safe per trust scope rules.
  • [COMMAND_EXECUTION]: The skill executes project-specific commands (installing dependencies, starting preview builds) and performs UI inspection. These actions are aligned with the skill's primary purpose of reviewing local web projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data (source code, screenshots, Figma links). While this presents a low-level vulnerability surface for indirect injection, the risk is inherent to tools that analyze external content and is mitigated by the skill's focus on structured UI review rather than execution of commands embedded in those assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:47 AM
Security Audit — agent-trust-hub — interface-review