ui-design-and-polish
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content, including code, documentation, and
AGENTS.mdfiles, which could contain malicious instructions designed to hijack the agent's behavior. - Ingestion points: The skill reads repository documentation, routes, entrypoints, components, layouts, styles, tokens, tests, and
AGENTS.mdfiles (SKILL.md, Establish product and repository truth). - Boundary markers: Absent. The instructions do not specify delimiters or provide warnings to ignore embedded instructions within the ingested data.
- Capability inventory: The skill is authorized to modify files for UI refinement and redesign, and it can execute shell commands discovered in the repository (visual-verification.md).
- Sanitization: Absent. There is no requirement or guidance for the agent to sanitize or filter content read from the repository before processing it.
- [COMMAND_EXECUTION]: The skill allows the agent to execute "repository-discovered safe commands" for visual verification. While the instructions include a requirement to inspect commands for safety before execution (visual-verification.md), this capability could be exploited if a malicious repository contains deceptive command names or scripts.
Audit Metadata