design-ux
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and documentation for a model to follow when performing a heuristic evaluation of a user interface.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No instances of hardcoded credentials, sensitive file path access, or network exfiltration patterns were detected. All URL references are to public documentation or source repositories.
- [REMOTE_CODE_EXECUTION]: There are no commands that download or execute remote scripts (e.g., curl | bash), nor any package installation instructions (npm, pip).
- [PROMPT_INJECTION]: The instructions do not attempt to bypass safety filters, override system prompts, or extract internal configuration. The language is focused on the intended task of usability auditing.
- [INDIRECT_PROMPT_INJECTION]: While the skill instructs the agent to process external data (rendered UIs and interaction traces), it does not possess or utilize dangerous capabilities such as arbitrary command execution or file system modifications, neutralizing the risk of indirect injection.
- [EXTERNAL_DOWNLOADS]: The skill mentions external documentation from a well-known service (Vercel Labs), which is used solely as a reference for UX best practices.
Audit Metadata