skills/ssheleg/super-ux/ux-audit/Gen Agent Trust Hub

ux-audit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill audits external codebase files by reading specific lines to verify implementation against scenarios. This ingestion of potentially untrusted data represents a surface for indirect prompt injection attacks, where malicious instructions embedded in the code could influence agent behavior. * Ingestion points: Project codebase files read during audit passes. * Boundary markers: The skill emphasizes evidence discipline, but does not specify explicit sanitization or instruction-ignoring wrappers for ingested code content. * Capability inventory: Spawning subagents for batch auditing, writing report files, and utilizing Figma MCP tools. * Sanitization: Not implemented in the skill instructions.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing and utilizing vendor-owned tools and plugins, including 'ssheleg/task-pipeline' and 'ssheleg/sheleg-design-skill'. These are identified as legitimate resources from the authorized vendor 'ssheleg' and represent standard extension of functionality.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of local scripts for linting ('docs/ux/lint.py', 'docs/brand/lint.py') and utilizes vendor-specific CLI tools via 'npx'. These operations are consistent with the skill's primary purpose of codebase auditing and task management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:58 AM
Security Audit — agent-trust-hub — ux-audit