ui-workflow

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for setting up MCP servers using the gcloud CLI and claude mcp add. These are standard administrative tasks for integrating Google Cloud services and browser automation.
  • [EXTERNAL_DOWNLOADS]: Instructions include the use of npx to run shadcn, stitch-mcp, and @playwright/mcp. These tools are standard in the web development ecosystem and originate from well-known sources or reputable organizations like Microsoft.
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs users to avoid hardcoding credentials, recommending the use of Google Cloud's Application Default Credentials (gcloud auth application-default login), which is a security best practice.
  • [PROMPT_INJECTION]: The skill processes user-provided UI requirements to generate PRDs and code. While this represents an indirect prompt injection surface, it is a functional requirement for the design workflow and lacks suspicious capability chains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:06 AM
Security Audit — agent-trust-hub — ui-workflow