ux-audit-skill

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data such as URLs and source code, creating an indirect prompt injection surface. While it uses strict evidence models and templates to structure its findings, it does not define explicit boundary markers or instructions to disregard directives embedded in the audited assets. Ingestion points: URLs, screenshots, and source code. Boundary markers: absent. Capability inventory: shared local tools. Sanitization: absent.
  • [COMMAND_EXECUTION]: The documentation includes shell commands for skill validation and linting using local scripts. These are intended for developer verification of the skill's structure and do not pose a runtime threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:31 AM
Security Audit — agent-trust-hub — ux-audit-skill