salla-app-ui-builder
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behaviors, obfuscation, or unauthorized access patterns were detected. The skill is consistent with its stated purpose of providing a UI builder for the Salla App Store.
- [PROMPT_INJECTION]: The skill processes user-provided content for public display, creating a surface for indirect injection. 1. Ingestion points: Element values such as name, description, and richtext processed via the app_page_builder action=set tool (SKILL.md, references/payloads.md). 2. Boundary markers: Absent; the instructions do not specify the use of delimiters or markers for the content strings provided by the user. 3. Capability inventory: The skill utilizes tools to write directly to the app's draft publication, which is a public-facing entity (references/api-spec.md). 4. Sanitization: The documentation explicitly instructs the agent to use only trusted and sanitized assets/HTML for public content (SKILL.md, references/payloads.md).
Audit Metadata