uxui-evaluator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data which could contain malicious instructions.
  • Ingestion points: User-provided interface descriptions in SKILL.md (via the audit tool).
  • Boundary markers: Absent; no delimiters or warnings to ignore embedded instructions are provided in the skill body.
  • Capability inventory: The skill has network access capabilities via curl commands defined in the SKILL.md toolbox.
  • Sanitization: Absent; the skill does not specify any escaping, validation, or filtering of the external content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:22 PM
Security Audit — agent-trust-hub — uxui-evaluator