ui-design
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides explicit shell command templates using
curl,wget, andInvoke-WebRequestfor the agent to download remote assets such as images, icons, and fonts from external URLs into the project workspace. While the instructions recommend well-known services, the generic command structure allows for downloading files from any source. - [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands (
grep) to perform self-audits on generated code files to detect forbidden colors, fonts, and icons. This encourages the agent to invoke shell processes to inspect local files. - [INDIRECT_PROMPT_INJECTION]: The skill processes user requirements and external assets to generate UI designs without explicit sanitization or boundary markers, creating a surface for instructions embedded in user-supplied data or downloaded assets.
- Ingestion points: User requirements for UI design and external assets (images, icons, fonts) fetched via network operations.
- Boundary markers: Not present for user-supplied design requirements.
- Capability inventory: Shell command execution (
curl,wget,grep,Invoke-WebRequest) and file system access. - Sanitization: No validation or sanitization logic is defined for the content of downloaded assets or user-provided design descriptions.
Audit Metadata