skills/ssheleg/super-ux/ux-foundation/Gen Agent Trust Hub

ux-foundation

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends running local linter scripts (python3 docs/ux/lint.py) and index generators (python3 plugins/super-ux/scripts/bp_index.py). These are standard project-level management scripts.
  • [EXTERNAL_DOWNLOADS]: Instructions include installing optional companion tools (sheleg-design-skill, task-pipeline) from the same vendor using npx or plugin marketplace commands. These resources are identified as part of the vendor's own framework ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from store reviews and support tickets to extract user pain points for journey mapping. While this constitutes an ingestion surface, the processing is confined to generating markdown documentation and does not bridge to high-privilege operations.
  • [REMOTE_CODE_EXECUTION]: Mirrored design tasks utilize the use_figma MCP tool to execute JavaScript against the Figma Plugin API. This behavior is within the expected functional scope for design automation as defined in the skill's integration references.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 03:19 PM
Security Audit — agent-trust-hub — ux-foundation