ui-ux-audit

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted content from the project's source code directory, which creates an indirect prompt injection attack surface.
  • Ingestion points: The skill instructions mandate reading files from src/app/, src/components/, and src/data/ as well as using grep to search for keywords.
  • Capability inventory: The skill is capable of reading local files and generating structured markdown reports. It does not appear to possess network access or arbitrary command execution capabilities in the provided scripts.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" markers when processing the content of these files.
  • Sanitization: There is no evidence of sanitization or filtering of the content read from the source files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — ui-ux-audit