ui-reverse-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from third-party websites (HTML, CSS, and JS), which is an inherent risk factor for indirect prompt injection attacks.
  • Ingestion points: Data enters the agent's context through files like structure.json, styles.json, interactions-detected.json, and downloaded JS/CSS chunks.
  • Boundary markers: The skill explicitly uses delimiters (═══ BEGIN/END EXTRACTED DATA ═══) in css-first-generation.md to isolate untrusted content.
  • Capability inventory: The skill uses agent-browser for web interaction, curl for downloads, and bash/python for local pipeline management.
  • Sanitization: The instructions in dom-extraction.md and interaction-detection.md include grep-based checks to detect and neutralize common injection markers such as "ignore previous instructions" or "you are now".
  • [EXTERNAL_DOWNLOADS]: The skill downloads assets (CSS, JS bundles, fonts, images) from user-provided URLs during the extraction process.
  • Mitigations: Downloads are restricted to HTTPS, enforce a 10MB size limit per file, and have 30s timeouts. It explicitly warns against forwarding credentials or cookies during these operations in asset-extraction.md.
  • [COMMAND_EXECUTION]: The skill executes local scripts and binary tools (FFmpeg, ImageMagick, Python modules) to process visual data and manage the reverse-engineering pipeline.
  • Vendor patterns: Setup instructions in session-setup.md reference a bootstrap script at https://raw.githubusercontent.com/voidmatcha/ui-clone-skills/main/install.sh. This is a vendor-owned resource (voidmatcha) and is documented as a manual setup step for the user rather than an automated execution by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:20 AM
Security Audit — agent-trust-hub — ui-reverse-engineering