ui-ux-pro-max

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides detailed and professional design guidance for web and mobile development, covering accessibility, layout, and visual styles across multiple technology stacks.
  • [COMMAND_EXECUTION]: The skill executes a local Python script (search.py) to perform design database queries and manage the persistence of design systems in the design-system/ directory. It also provides instructions for setting up the required Python environment on various operating systems.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes user-supplied search queries and incorporates rules from local configuration files (MASTER.md and page-specific overrides) into the agent's context. This is a intended feature for design consistency management.
  • Ingestion points: User-provided search parameters and local markdown files in the design-system/ directory.
  • Boundary markers: None explicitly defined in the provided retrieval instructions or templates.
  • Capability inventory: Local subprocess execution of the search.py script and file system operations within the skill's data directory.
  • Sanitization: No explicit content sanitization or validation of the design rules is performed by the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 02:49 PM
Security Audit — agent-trust-hub — ui-ux-pro-max