cocos24-ui

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted UI screenshots to generate TypeScript code, which creates a surface for indirect prompt injection.\n
  • Ingestion points: UI screenshots provided by the user in the agent context.\n
  • Boundary markers: Absent (instructions do not specify delimiters for vision data).\n
  • Capability inventory: Generates UI control classes and data models in TypeScript.\n
  • Sanitization: Relies on the base model's safety filters for image processing.\n- [NO_CODE]: Although the documentation references several TypeScript components (e.g., LoadAsset.ts, UIManager.ts), these files are not included in the provided skill package.\n- [SAFE]: No patterns of data exfiltration, credential theft, or unauthorized command execution were detected. The skill primarily functions as a coding assistant and documentation guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 06:02 AM
Security Audit — agent-trust-hub — cocos24-ui