ui-workflow
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for setting up MCP servers using the
gcloudCLI andclaude mcp add. These are standard administrative tasks for integrating Google Cloud services and browser automation. - [EXTERNAL_DOWNLOADS]: Instructions include the use of
npxto runshadcn,stitch-mcp, and@playwright/mcp. These tools are standard in the web development ecosystem and originate from well-known sources or reputable organizations like Microsoft. - [CREDENTIALS_UNSAFE]: The skill explicitly instructs users to avoid hardcoding credentials, recommending the use of Google Cloud's Application Default Credentials (
gcloud auth application-default login), which is a security best practice. - [PROMPT_INJECTION]: The skill processes user-provided UI requirements to generate PRDs and code. While this represents an indirect prompt injection surface, it is a functional requirement for the design workflow and lacks suspicious capability chains.
Audit Metadata