uikit

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to retrieve documentation from a third-party domain (sosumi.ai) that is not on the trusted or whitelisted domain lists. File: SKILL.md. Evidence: 'use the relevant documentation path from uikit-overview.md with the sosumi.ai Markdown mirror.'
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection by ingesting untrusted data from an external mirror. 1. Ingestion points: Remote markdown files fetched from sosumi.ai as specified in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Local searching via ripgrep (rg) and processing markdown content; no dangerous command execution or file system writes identified in provided files. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:30 PM
Security Audit — agent-trust-hub — uikit