mobile-ui-design
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is focused on generating design documentation and prompts for external image tools. It does not include any scripts, executables, or commands that interact with the host system or network.
- [SAFE]: It provides explicit instructions to the agent to avoid editing application code or agent configuration files, which prevents accidental or malicious code modification.
- [SAFE]: The skill instructions demonstrate defensive design principles by distinguishing visual 'pledges' from actual security mechanisms like biometric authentication or OAuth, preventing user confusion and potential security misrepresentation.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the project codebase, briefs, and existing routes, creating a surface for indirect prompt injection. However, the risk is negligible as capabilities are restricted to document generation. Ingestion points: project codebase, design briefs, and existing routes; Boundary markers: absent; Capability inventory: file writes limited to documentation in the docs/design/ directory; Sanitization: absent.
- [SAFE]: No obfuscation, data exfiltration, persistence mechanisms, or privilege escalation patterns were found.
Audit Metadata