skills/tw93/waza/ui/Gen Agent Trust Hub

ui

Fail

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to offer and potentially execute 'npx getdesign@latest add '. This command downloads and runs code from the NPM registry provided by a third party ('VoltAgent'). Since 'VoltAgent' is not a pre-verified trusted vendor, this pattern represents a remote code execution risk.\n- [COMMAND_EXECUTION]: The skill includes shell command strings ('npx getdesign...') for project setup and brand preset integration as part of its recommended workflow.\n- [EXTERNAL_DOWNLOADS]: The skill references and fetches design assets and code from an external repository ('github.com/VoltAgent/awesome-design-md') via a CLI tool, bypassing standard dependency verification.\n- [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection by ingesting and acting upon user-supplied external data.\n
  • Ingestion points: User-provided repository URLs and source code pastes in SKILL.md ('Source repo as reference' section), and user-supplied screenshots in references/mode-screenshot-iteration.md.\n
  • Boundary markers: There are no explicit instructions or markers provided to the agent to distinguish between legitimate design data and potentially malicious instructions embedded within the ingested code or visual evidence.\n
  • Capability inventory: The agent has the capability to execute shell commands ('npx') and generate/modify project files based on the ingested content.\n
  • Sanitization: The skill does not define any validation or sanitization procedures for the external code or screenshot data before it is processed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 9, 2026, 02:03 AM
Security Audit — agent-trust-hub — ui