cocos24-ui
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted UI screenshots to generate TypeScript code, which creates a surface for indirect prompt injection.\n
- Ingestion points: UI screenshots provided by the user in the agent context.\n
- Boundary markers: Absent (instructions do not specify delimiters for vision data).\n
- Capability inventory: Generates UI control classes and data models in TypeScript.\n
- Sanitization: Relies on the base model's safety filters for image processing.\n- [NO_CODE]: Although the documentation references several TypeScript components (e.g., LoadAsset.ts, UIManager.ts), these files are not included in the provided skill package.\n- [SAFE]: No patterns of data exfiltration, credential theft, or unauthorized command execution were detected. The skill primarily functions as a coding assistant and documentation guide.
Audit Metadata