ux-audit
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a placeholder (
$ARGUMENTS) to ingest external data for analysis, creating a surface for indirect prompt injection. Malicious instructions embedded within the user-provided screen descriptions or code could potentially influence the agent's behavior during the audit. * Ingestion points: TheTarget: **$ARGUMENTS**field inSKILL.md. * Boundary markers: The skill does not provide clear delimiters or instructions to the agent to treat the argument content as untrusted data or to ignore instructions within it. * Capability inventory: The skill contains no scripts, binary executables, or network requests, limiting the potential impact of an injection. * Sanitization: There are no explicit validation or sanitization steps defined for the input data.
Audit Metadata