interface-craft

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, persistence mechanisms, or privilege escalation attempts were detected. The skill is well-scoped to interface design and user experience improvements.
  • [PROMPT_INJECTION]: The skill processes user-provided UI code, interaction states, and screenshots, which constitutes a surface for indirect prompt injection. This risk is managed through a 'restraint gate' and a set of guardrails that require all proposed changes to be validated against accessibility and consistency standards. 1. Ingestion points: UI source code and interaction data are ingested in the workflow described in SKILL.md. 2. Boundary markers: The instructions include a restraint gate and explicit 'When not to use' constraints to define behavioral boundaries. 3. Capability inventory: The skill is restricted to generating UI review findings and implementing minor interface improvements. 4. Sanitization: The skill uses instructional constraints to ensure the agent remains focused on UI polish rather than following potential instructions embedded in the processed code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:07 AM
Security Audit — agent-trust-hub — interface-craft