ui-pattern-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a systematic pipeline for analyzing untrusted external data, specifically user-provided source code and screenshots. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the processed data. The skill provides a structured classification framework which helps in objective analysis.
  • Ingestion points: User-provided code and screenshots analyzed via the /audit command.
  • Boundary markers: The skill instructs the agent to map data to a specific taxonomy, providing a level of structural isolation through classification.
  • Capability inventory: The skill itself contains no executable code or tool definitions; it provides instructions for the agent's existing commands (e.g., /audit, /ship, /tokens).
  • Sanitization: The systematic categorization process acts as a functional filter for incoming data.
  • [EXTERNAL_DOWNLOADS]: The skill references a wide variety of well-known and trusted technology products, libraries, and services (e.g., Stripe, Linear, Notion, Vercel, Radix UI, cmdk) as industry benchmarks. These references are purely informative and do not involve unauthorized downloads or executions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 07:32 AM
Security Audit — agent-trust-hub — ui-pattern-intelligence