ui-design-and-polish

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content, including code, documentation, and AGENTS.md files, which could contain malicious instructions designed to hijack the agent's behavior.
  • Ingestion points: The skill reads repository documentation, routes, entrypoints, components, layouts, styles, tokens, tests, and AGENTS.md files (SKILL.md, Establish product and repository truth).
  • Boundary markers: Absent. The instructions do not specify delimiters or provide warnings to ignore embedded instructions within the ingested data.
  • Capability inventory: The skill is authorized to modify files for UI refinement and redesign, and it can execute shell commands discovered in the repository (visual-verification.md).
  • Sanitization: Absent. There is no requirement or guidance for the agent to sanitize or filter content read from the repository before processing it.
  • [COMMAND_EXECUTION]: The skill allows the agent to execute "repository-discovered safe commands" for visual verification. While the instructions include a requirement to inspect commands for safety before execution (visual-verification.md), this capability could be exploited if a malicious repository contains deceptive command names or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:52 PM
Security Audit — agent-trust-hub — ui-design-and-polish