skills/simota/agent-skills/palette/Gen Agent Trust Hub

palette

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive UX engineering guidelines, heuristic evaluation templates, and standard web development reference material. The code snippets included for features like dark mode, haptic feedback, and the WebAuthn API are industry-standard implementation examples. No malicious code, prompt injection, or data exfiltration patterns were detected.- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface when processing AI-generated UI components. 1. Ingestion points: UI specifications and AI-generated HTML content (reference/ai-assist-patterns.md). 2. Boundary markers: The instructions mandate 'Intent Previews' and 'Action Audits' to provide behavioral guardrails for autonomous actions. 3. Capability inventory: The skill is limited to UI design and interaction logic; implementation is delegated to a separate production agent. 4. Sanitization: The skill explicitly requires sanitizing all AI-generated structure using DOMPurify before rendering to prevent script injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — palette