emil-design-eng

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing a persona and specific design rules for reviewing UI code. It does not contain executable scripts, external dependencies, or network-enabled tools.
  • [PROMPT_INJECTION]: The skill uses behavioral constraints (e.g., 'Do not provide any other information until the user asks a question') and a mandatory output format (markdown table) to maintain its persona. These are standard alignment instructions and do not represent attempts to bypass security filters or override agent safety protocols.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or data exfiltration logic were found. The external links provided (e.g., animations.dev, easing.dev) are legitimate design resources related to the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data because its primary function is to review user-provided UI code. However, the skill possesses no capabilities for code execution, file modification, or network requests, which significantly limits the risk of an indirect prompt injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 07:31 AM
Security Audit — agent-trust-hub — emil-design-eng