ux-scenarios
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run a local Python linter (
python3 docs/ux/lint.py) to ensure documentation consistency. This is a standard validation practice for this methodology. - [INDIRECT_PROMPT_INJECTION]: In the 'Init (existing code)' workflow, the agent is instructed to perform an inventory sweep of the target project's codebase. This processes external, potentially untrusted data which could contain malicious instructions. However, the skill primarily uses this data for documentation mapping and does not include mechanisms for automatic execution of discovered code.
- Ingestion points: Codebase inventory sweep during initialization (SKILL.md).
- Boundary markers: None identified.
- Capability inventory: File read/write, local command execution (python3).
- Sanitization: None identified.
- [EXTERNAL_DOWNLOADS]: The documentation mentions external resources like the sheleg-design skill and Figma MCP, but these are provided as user-verified recommendations or optional integrations rather than automated remote code execution triggers.
Audit Metadata