skills/tinh2/skills-hub-registry/ux/Gen Agent Trust Hub

ux

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the ingestion of untrusted data such as design mockups, screenshots, and brand guidelines. Malicious instructions embedded in these visual or textual inputs could influence the agent's behavior.\n
  • Ingestion points: External mockups, screenshots, Figma frames, and design specifications (referenced in Phase 1 of Mode 2).\n
  • Boundary markers: The instructions do not define clear delimiters or warning markers when processing external design inputs.\n
  • Capability inventory: The skill possesses filesystem read access for auditing, and write/commit access for applying fixes (Phase 6 and Phase 3 of Mode 2).\n
  • Sanitization: There is no mechanism described for sanitizing or validating the content of external design files before they are analyzed for implementation.\n- [COMMAND_EXECUTION]: The skill performs autonomous filesystem writes and git commits. It is programmed to identify UX/UI issues and immediately apply fixes to the code, followed by executing git commands to commit the changes.\n- [COMMAND_EXECUTION]: The skill attempts to write execution metadata to a telemetry file in the user's home directory (~/.claude/projects/). This behavior involves accessing and modifying files outside of the target project repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:59 AM
Security Audit — agent-trust-hub — ux