msw-ui-system

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill uses standard Node.js file system modules to create and modify UI configuration files and Lua scripts within the project workspace, which is consistent with its stated purpose as a developer tool.
  • [DYNAMIC_EXECUTION]: The builder script (msw_ui_builder.cjs) uses require to load a local linting module. The path is computed relative to the script's own directory (__dirname), which is a safe pattern for loading internal dependencies within a skill package.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains logic to modify project .mlua files by injecting UI component identifiers (UUIDs) into property declarations. This capability is restricted to specific regex-based property assignments, serving the legitimate purpose of synchronizing UI files with their corresponding logic scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 11:12 PM