ui-design

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides explicit shell command templates using curl, wget, and Invoke-WebRequest for the agent to download remote assets such as images, icons, and fonts from external URLs into the project workspace. While the instructions recommend well-known services, the generic command structure allows for downloading files from any source.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run shell commands (grep) to perform self-audits on generated code files to detect forbidden colors, fonts, and icons. This encourages the agent to invoke shell processes to inspect local files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user requirements and external assets to generate UI designs without explicit sanitization or boundary markers, creating a surface for instructions embedded in user-supplied data or downloaded assets.
  • Ingestion points: User requirements for UI design and external assets (images, icons, fonts) fetched via network operations.
  • Boundary markers: Not present for user-supplied design requirements.
  • Capability inventory: Shell command execution (curl, wget, grep, Invoke-WebRequest) and file system access.
  • Sanitization: No validation or sanitization logic is defined for the content of downloaded assets or user-provided design descriptions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 03:41 PM
Security Audit — agent-trust-hub — ui-design