ui-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection because it is designed to ingest and validate external source code files using the regex patterns defined in its reference files. Although the skill processes untrusted data, the risk is negligible as it lacks any capabilities to perform dangerous actions such as network requests or file modifications.
- Ingestion points: User-provided code files (e.g.,
*.tsx,*.jsx,*.css) specified inreferences/validations.md. - Boundary markers: Not present.
- Capability inventory: No file-write, network, or shell execution capabilities identified in the skill scripts or instructions.
- Sanitization: The skill does not sanitize or escape the content of the files it validates.
Audit Metadata