ui-design

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The 'SELF-AUDIT CHECKLIST' in SKILL.md instructs the agent to execute shell commands like grep -iE to scan generated files for forbidden aesthetic elements.
  • [EXTERNAL_DOWNLOADS]: The 'Downloading Remote Assets' section directs the agent to use curl or Invoke-WebRequest to download files from arbitrary remote URLs. The skill documentation explicitly states these shell-based methods should be used because a built-in tool was removed due to 'SSRF filtering' errors, indicating an intentional bypass of security controls.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user requirements to generate code and trigger network/file operations. 1. Ingestion points: User-provided design requirements processed by instructions in SKILL.md. 2. Boundary markers: Uses a 'DESIGN SPECIFICATION' header to structure output, but lacks markers for incoming data. 3. Capability inventory: File system writes, local shell execution (grep), and network downloads (curl/wget). 4. Sanitization: No validation or escaping is specified for user-provided design tokens before they are used in code generation or asset naming.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — ui-design