ui-ux-pro-max

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Path traversal vulnerability in scripts/design_system.py. The persist_design_system function constructs file paths using user-controlled input from the project_name and page arguments. Because these inputs are not sanitized for directory traversal characters (such as ../ or /), and the script uses Path.mkdir(parents=True), an attacker could potentially create directories and write MASTER.md or page-specific markdown files in arbitrary locations on the file system relative to the execution root.
  • [EXTERNAL_DOWNLOADS]: The documentation in SKILL.md and its variants recommends installing the Python 3 runtime using established system package managers including Homebrew, APT, and WinGet. These are recognized as well-known and trusted sources for development dependencies.
  • [COMMAND_EXECUTION]: The skill's primary functionality relies on executing a local Python script (scripts/search.py) to search UI/UX data stored in CSV format. This represents the intended operational behavior of the skill and is documented for the user.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 08:28 PM
Security Audit — agent-trust-hub — ui-ux-pro-max