uiux-implementation-qa

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements safety guidelines for the agent, explicitly requiring the redaction of secrets from logs and fixtures. It also establishes a clear boundary by instructing the agent to treat repository files and external content as data, not instructions.
  • [COMMAND_EXECUTION]: The skill includes a test utility in scripts/tests/test_checklist_design_catalogue.py that uses subprocess.run to call a local verification script (verify_checklist_design_catalogue.py). This is a standard and benign use of command execution for verifying the integrity of the bundled design checklists.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface related to the ingestion of UI/UX plans, codebase maps, and third-party checklists from Checklist.Design. However, it incorporates specific mitigation instructions, such as using boundary markers, following an approved manifest, and treating all rendered or source evidence as non-authoritative for security claims.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 06:16 AM
Security Audit — agent-trust-hub — uiux-implementation-qa