interface-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill does not contain any detected malicious patterns, obfuscation, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted interface descriptions provided by users, which are then used to determine tool parameters for UX smell lookups. This constitutes a standard input processing surface.
  • Ingestion points: Interface descriptions extracted in Step 1 of the audit workflow in SKILL.md.
  • Boundary markers: None explicitly defined for user input.
  • Capability inventory: Tool-based network access (curl) to the author's domain via list_smells and lookup_smell definitions.
  • Sanitization: The skill maps user input to a fixed internal taxonomy before invoking tools, providing a layer of validation.
  • [EXTERNAL_DOWNLOADS]: The skill optionally fetches extended UX remediation data from the author's official domain (uxuiprinciples.com) using an API key provided via environment variables. This is consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:22 PM
Security Audit — agent-trust-hub — interface-auditor