ui-review
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides purely instructional content for UI and UX auditing. No malicious patterns, command execution, or data exfiltration vectors were identified in the markdown instructions.
- [PROMPT_INJECTION]: The skill is designed to process untrusted external data such as component code and screenshots. While this is an attack surface for indirect prompt injection, no exploitable capabilities are associated with this skill.
- Ingestion points: Processes screenshots, rendered pages, and component code (SKILL.md).
- Boundary markers: No explicit delimiters are used for user-provided data.
- Capability inventory: The skill lacks file write, network access, and shell execution capabilities.
- Sanitization: The instructions do not specify any validation or sanitization for external content.
Audit Metadata