ux-empty-states
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill acts as a UX consultant, ingesting untrusted data provided by the user (e.g., UI screen descriptions or design requests) as specified in SKILL.md.
- Ingestion points: User design requests and UI descriptions.
- Boundary markers: None provided in the instructions.
- Capability inventory: No file system access, network operations, or subprocess execution capabilities were found.
- Sanitization: No input sanitization or validation logic is present.
- Assessment: While an indirect prompt injection surface exists, the lack of dangerous capabilities limits the potential impact to misbehavior within the chat context.
- [EXTERNAL_DOWNLOADS]: The skill references an external lesson at
https://uxcel.com/lessons/empty-states-best-practices-330. This is the official domain of the skill author and is used to provide relevant UX educational content. This reference is considered safe and does not involve remote code execution.
Audit Metadata