mobile-ui-development-rule
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a mandatory protocol for reading and recording state, which introduces a data ingestion surface.
- Ingestion points: The instructions in SKILL.md mandate reading from
.claude/context/memory/learnings.mdat the start of each session. - Boundary markers: The skill lacks delimiters or explicit instructions to treat the ingested memory content as untrusted data.
- Capability inventory: The skill is granted
Read,Write, andEdittools in its frontmatter (SKILL.md), which could be misused if the agent is influenced by malicious content in the memory file. - Sanitization: There is no evidence of sanitization, filtering, or validation for the content stored in or read from the memory file.
Audit Metadata