refactoring-ui
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing and improvement of user-provided UI code and design requests, which represents an ingestion surface for untrusted data that could attempt to influence the agent's behavior. \n
- Ingestion points: User-supplied UI code, dashboard layouts, and design feedback provided to the agent during styling tasks as described in SKILL.md and references/diagnose.md. \n
- Boundary markers: The skill does not define specific delimiters or instructions to explicitly ignore embedded commands within the processed UI code blocks. \n
- Capability inventory: The skill is composed of instructions and CSS tokens; it does not add custom tools for shell execution, file system modification, or network operations. \n
- Sanitization: No validation or sanitization routines are provided for the user-supplied UI data before it is evaluated against the design rules.
Audit Metadata