ui-score

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a static analysis tool for UI design auditing. It evaluates code based on predefined weights for hierarchy, layout, color discipline, and accessibility.
  • [DATA_EXPOSURE]: There is no evidence of sensitive file access (e.g., .ssh, .aws) or hardcoded credentials. The network operations are limited to the metadata's source references.
  • [COMMAND_EXECUTION]: The skill references internal agent commands like /ss-review and /ss-lint. These are modular components of the StyleSeed framework and do not represent arbitrary command execution risk.
  • [PROMPT_INJECTION]: No patterns of safety filter bypass or role-play-based jailbreaks were identified in the instructions. The 'Gate mode' is a legitimate iterative refinement loop.
  • [PROMPT_INJECTION]: (Indirect Surface) The skill processes external UI files which could theoretically contain malicious instructions.
  • Ingestion points: Local UI files (e.g., .tsx, .css) analyzed by the agent.
  • Boundary markers: None explicitly defined in the prompt template.
  • Capability inventory: File editing via internal tool integration (/ss-review).
  • Sanitization: None defined for external content, though the analysis is constrained by design scoring rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 11:33 AM
Security Audit — agent-trust-hub — ui-score