ux-foundation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process untrusted external data such as store reviews and support tickets to inform customer journeys.
- Ingestion points:
SKILL.md(instructions to read store reviews and support queue),research-evidence.md(synthesis of research findings into the foundation). - Boundary markers: Absent. No specific delimiters or "ignore embedded instructions" warnings are provided for the ingested external text.
- Capability inventory: The skill executes local Python scripts (
docs/ux/lint.py), performs file I/O operations, and invokes various Figma MCP tools. - Sanitization: Absent. The skill does not prescribe specific validation, escaping, or filtering of the external content before it is interpolated into the agent's context.
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of external companion plugins and packages.
- Evidence:
visual-identity.mdandsystem-map.mdsuggest the installation ofsheleg-design-skillandtask-pipelineusing commands like/plugin install sheleg-design@sheleg-design-skillandnpx sheleg-design-skill. - Note: These resources are identified as vendor-owned tools belonging to the author
sshelegand represent expected functionality for this ecosystem. - [COMMAND_EXECUTION]: The skill involves the execution of local utility scripts for maintenance.
- Evidence:
SKILL.mdspecifies the use ofpython3 docs/ux/lint.pyto validate project documentation. This is a standard developer tool pattern for maintaining documentation consistency.
Audit Metadata