ux-audit
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates primarily on local documentation files (
docs/ux/*.md,docs/brand/*.md) and source code to perform static analysis and audit tracing. No unexpected network operations or sensitive data access patterns were identified.- [SAFE]: External dependencies and references target trusted organizations (e.g., Apple HIG, Material Design, W3C, Nielsen Norman Group) or the vendor's own tools ('ssheleg/task-pipeline'). These are used for documentation and implementation guidance, consistent with the skill's primary purpose.- [SAFE]: The skill enforces secure practices for secrets by instructing users to store credentials in.envfiles rather than hardcoding them, and it includes checks for 'ai-tells' to detect machine-generated content markers.- [SAFE]: No obfuscation, base64-encoded payloads, or hidden commands were found in the instructions or reference files. The logic is transparent and focused on UX methodology.- [SAFE]: The 'Dynamic Context Injection' pattern (!command) is used legitimately in the documentation to demonstrate how to integrate standard development tools likegitorgh, with no evidence of malicious command injection or silent execution.
Audit Metadata