ui-snapshot
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates entirely on the local codebase, reading UI component files and writing pattern summaries to a markdown file located at context/ui-registry.md. It does not perform network operations, execute arbitrary code, or access sensitive system directories.
- [PROMPT_INJECTION]: This skill has an indirect prompt injection surface as it processes code from component files that could contain malicious instructions. The risk is minimized by the skill's limited capability set, which is restricted to local documentation tasks. 1. Ingestion: Component files scanned during standard and audit modes. 2. Boundary markers: None present. 3. Capability inventory: Reading project files and writing to context/ui-registry.md. 4. Sanitization: None present.
Audit Metadata