refactoring-ui

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing and improvement of user-provided UI code and design requests, which represents an ingestion surface for untrusted data that could attempt to influence the agent's behavior. \n
  • Ingestion points: User-supplied UI code, dashboard layouts, and design feedback provided to the agent during styling tasks as described in SKILL.md and references/diagnose.md. \n
  • Boundary markers: The skill does not define specific delimiters or instructions to explicitly ignore embedded commands within the processed UI code blocks. \n
  • Capability inventory: The skill is composed of instructions and CSS tokens; it does not add custom tools for shell execution, file system modification, or network operations. \n
  • Sanitization: No validation or sanitization routines are provided for the user-supplied UI data before it is evaluated against the design rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:11 AM
Security Audit — agent-trust-hub — refactoring-ui