ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides detailed and professional design guidance for web and mobile development, covering accessibility, layout, and visual styles across multiple technology stacks.
- [COMMAND_EXECUTION]: The skill executes a local Python script (
search.py) to perform design database queries and manage the persistence of design systems in thedesign-system/directory. It also provides instructions for setting up the required Python environment on various operating systems. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes user-supplied search queries and incorporates rules from local configuration files (
MASTER.mdand page-specific overrides) into the agent's context. This is a intended feature for design consistency management. - Ingestion points: User-provided search parameters and local markdown files in the
design-system/directory. - Boundary markers: None explicitly defined in the provided retrieval instructions or templates.
- Capability inventory: Local subprocess execution of the
search.pyscript and file system operations within the skill's data directory. - Sanitization: No explicit content sanitization or validation of the design rules is performed by the skill's instructions.
Audit Metadata