ui-ux-pro-max

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's persistence mechanism in scripts/design_system.py contains a path traversal vulnerability.
  • The function persist_design_system uses the project_name and page arguments to construct file paths for saving design systems.
  • These inputs are processed only with basic character replacement (replace(' ', '-')) and are not sanitized for directory traversal sequences like ../.
  • An attacker could potentially manipulate the agent into providing a malicious project name (e.g., ../../target_dir), allowing the script to create directories or write files (with a .md extension) outside the intended design-system/ folder.
  • [SAFE]: The skill operates entirely locally using a BM25 search engine implemented in scripts/core.py to query design guidelines from provided CSV files.
  • [SAFE]: All external URLs found in the skill data point to official documentation for well-known and trusted services such as Next.js, Astro, Tailwind CSS, and Google Fonts.
  • [SAFE]: The skill's instructions include standard prerequisite setup commands for installing Python via official package managers (brew, apt, winget).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 11:57 AM
Security Audit — agent-trust-hub — ui-ux-pro-max