mobile-ui-blueprint

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external data (such as product briefs, codebase files, and reference assets) which may contain hidden or malicious instructions meant to influence agent behavior.
  • Ingestion points: In SKILL.md, the instructions mandate that the agent "Inspect any supplied brief, plan, codebase, screenshots, assets, or references."
  • Boundary markers: Absent. The instructions do not define delimiters or provide specific warnings to the agent to disregard instructions embedded within these external inputs.
  • Capability inventory: SKILL.md identifies capabilities for reading project files and writing outputs to both the local project directory (mobile-design.md) and system temporary directories (design-draft.md). It also mentions the potential availability and use of image-generation tools.
  • Sanitization: Absent. There is no evidence of logic or instructions to escape, validate, or filter content retrieved from the ingested external data.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to external resources for image generation if internal tools are unavailable.
  • Evidence: SKILL.md suggests using official image generation help pages from OpenAI and Google.
  • Status: These links target well-known and trusted services, presenting no security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:36 PM
Security Audit — agent-trust-hub — mobile-ui-blueprint