salla-app-ui-builder

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious behaviors, obfuscation, or unauthorized access patterns were detected. The skill is consistent with its stated purpose of providing a UI builder for the Salla App Store.
  • [PROMPT_INJECTION]: The skill processes user-provided content for public display, creating a surface for indirect injection. 1. Ingestion points: Element values such as name, description, and richtext processed via the app_page_builder action=set tool (SKILL.md, references/payloads.md). 2. Boundary markers: Absent; the instructions do not specify the use of delimiters or markers for the content strings provided by the user. 3. Capability inventory: The skill utilizes tools to write directly to the app's draft publication, which is a public-facing entity (references/api-spec.md). 4. Sanitization: The documentation explicitly instructs the agent to use only trusted and sanitized assets/HTML for public content (SKILL.md, references/payloads.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:23 PM
Security Audit — agent-trust-hub — salla-app-ui-builder