ui-pattern-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a systematic pipeline for analyzing untrusted external data, specifically user-provided source code and screenshots. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the processed data. The skill provides a structured classification framework which helps in objective analysis.
- Ingestion points: User-provided code and screenshots analyzed via the
/auditcommand. - Boundary markers: The skill instructs the agent to map data to a specific taxonomy, providing a level of structural isolation through classification.
- Capability inventory: The skill itself contains no executable code or tool definitions; it provides instructions for the agent's existing commands (e.g.,
/audit,/ship,/tokens). - Sanitization: The systematic categorization process acts as a functional filter for incoming data.
- [EXTERNAL_DOWNLOADS]: The skill references a wide variety of well-known and trusted technology products, libraries, and services (e.g., Stripe, Linear, Notion, Vercel, Radix UI, cmdk) as industry benchmarks. These references are purely informative and do not involve unauthorized downloads or executions.
Audit Metadata