gsd-ui-phase
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources which could contain malicious instructions.
- Ingestion points: The skill reads
~/.claude/gsd-core/workflows/ui-phase.md,~/.claude/gsd-core/references/ui-brand.md, and processes user-supplied$ARGUMENTS. - Boundary markers: There are no boundary markers or instructions to ignore embedded commands within the ingested content.
- Capability inventory: The skill is permitted to use
Bash,Agent,Write, andWebFetchtools as specified in theallowed-toolsmetadata. - Sanitization: There is no evidence of sanitization or input validation for the data retrieved from the files or arguments.
Audit Metadata