ui-ux-pro-max
Warn
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Path traversal vulnerability in
scripts/design_system.py. Thepersist_design_systemfunction constructs file paths using user-controlled input from theproject_nameandpagearguments. Because these inputs are not sanitized for directory traversal characters (such as../or/), and the script usesPath.mkdir(parents=True), an attacker could potentially create directories and writeMASTER.mdor page-specific markdown files in arbitrary locations on the file system relative to the execution root. - [EXTERNAL_DOWNLOADS]: The documentation in
SKILL.mdand its variants recommends installing the Python 3 runtime using established system package managers including Homebrew, APT, and WinGet. These are recognized as well-known and trusted sources for development dependencies. - [COMMAND_EXECUTION]: The skill's primary functionality relies on executing a local Python script (
scripts/search.py) to search UI/UX data stored in CSV format. This represents the intended operational behavior of the skill and is documented for the user.
Audit Metadata