ui-design
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The 'SELF-AUDIT CHECKLIST' in SKILL.md instructs the agent to execute shell commands like
grep -iEto scan generated files for forbidden aesthetic elements. - [EXTERNAL_DOWNLOADS]: The 'Downloading Remote Assets' section directs the agent to use
curlorInvoke-WebRequestto download files from arbitrary remote URLs. The skill documentation explicitly states these shell-based methods should be used because a built-in tool was removed due to 'SSRF filtering' errors, indicating an intentional bypass of security controls. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user requirements to generate code and trigger network/file operations. 1. Ingestion points: User-provided design requirements processed by instructions in SKILL.md. 2. Boundary markers: Uses a 'DESIGN SPECIFICATION' header to structure output, but lacks markers for incoming data. 3. Capability inventory: File system writes, local shell execution (grep), and network downloads (curl/wget). 4. Sanitization: No validation or escaping is specified for user-provided design tokens before they are used in code generation or asset naming.
Audit Metadata