new-ui-mock

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing tools using uv tool install from the author's repository at github.com/ReScienceLab/super-prototyping. This is a legitimate vendor-owned resource for this skill.
  • [COMMAND_EXECUTION]: The instructions include bash commands for project initialization, file copying, and running UI rendering tools (refkit). These commands are standard for the described mockup workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided feedback in the form of annotated screenshots.
  • Ingestion points: Section 4 describes reading annotations from screenshots pasted by the user.
  • Boundary markers: The skill explicitly instructs the agent to "Echo what you read each annotation as, before touching anything," which provides a human-in-the-loop verification step.
  • Capability inventory: The skill uses python3 to run generator scripts and shell commands for rendering, which provides a capability surface for malicious instructions if they were successfully injected.
  • Sanitization: The workflow requires the user to manually trigger the generator and visually verify the rendered output, mitigating the risk of silent execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:56 PM
Security Audit — agent-trust-hub — new-ui-mock