interface-craft
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, persistence mechanisms, or privilege escalation attempts were detected. The skill is well-scoped to interface design and user experience improvements.
- [PROMPT_INJECTION]: The skill processes user-provided UI code, interaction states, and screenshots, which constitutes a surface for indirect prompt injection. This risk is managed through a 'restraint gate' and a set of guardrails that require all proposed changes to be validated against accessibility and consistency standards. 1. Ingestion points: UI source code and interaction data are ingested in the workflow described in SKILL.md. 2. Boundary markers: The instructions include a restraint gate and explicit 'When not to use' constraints to define behavioral boundaries. 3. Capability inventory: The skill is restricted to generating UI review findings and implementing minor interface improvements. 4. Sanitization: The skill uses instructional constraints to ensure the agent remains focused on UI polish rather than following potential instructions embedded in the processed code.
Audit Metadata