uiux-visual-layout

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied product briefs and models to generate design documentation. It lacks explicit instructions for sanitizing external input or using boundary markers, which creates a potential surface for indirect prompt injection. 1. Ingestion points: User-provided briefs and models (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Writing markdown files (06-visual-direction.md, 08-screen-specs.md). 4. Sanitization: Absent.
  • [DYNAMIC_EXECUTION]: The skill generates isolated HTML/CSS/JS prototypes from local templates for design reviews. While this involves dynamic code generation, the instructions include explicit safeguards prohibiting these prototypes from performing destructive, external, paid, or persistent operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 06:17 AM
Security Audit — agent-trust-hub — uiux-visual-layout