cross-device-check
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its requirement to process untrusted project data and source code to perform UI audits.
- Ingestion points: The skill reads project configuration, distribution targets, and engine/runtime settings (SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the analyzed project files.
- Capability inventory: The skill is authorized to report defects and apply fixes to the project source code upon user approval (SKILL.md).
- Sanitization: There is no evidence of sanitization, validation, or escaping of the ingested project data before it is processed by the agent.
Audit Metadata