skills/sylphxai/skills/ui-review/Gen Agent Trust Hub

ui-review

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and analyze rendered UI flows, preview URLs, and browser console outputs. This creates a potential attack surface where malicious instructions could be embedded in the product UI or error logs being reviewed.
  • Ingestion points: The agent is instructed to analyze rendered evidence, product preview URLs, and browser console/page errors.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the UI content being analyzed, which increases the risk of the agent following instructions found in the data.
  • Capability inventory: The skill involves executing shell commands for linting, type checks, unit tests, and running browser-based verification scripts (e.g., browser-smoke.mjs).
  • Sanitization: The instructions do not specify any sanitization or validation logic for the external content processed during the review flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 10:49 AM
Security Audit — agent-trust-hub — ui-review