ui-reverse-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from third-party websites (HTML, CSS, and JS), which is an inherent risk factor for indirect prompt injection attacks.
- Ingestion points: Data enters the agent's context through files like
structure.json,styles.json,interactions-detected.json, and downloaded JS/CSS chunks. - Boundary markers: The skill explicitly uses delimiters (
═══ BEGIN/END EXTRACTED DATA ═══) incss-first-generation.mdto isolate untrusted content. - Capability inventory: The skill uses
agent-browserfor web interaction,curlfor downloads, andbash/pythonfor local pipeline management. - Sanitization: The instructions in
dom-extraction.mdandinteraction-detection.mdinclude grep-based checks to detect and neutralize common injection markers such as "ignore previous instructions" or "you are now". - [EXTERNAL_DOWNLOADS]: The skill downloads assets (CSS, JS bundles, fonts, images) from user-provided URLs during the extraction process.
- Mitigations: Downloads are restricted to HTTPS, enforce a 10MB size limit per file, and have 30s timeouts. It explicitly warns against forwarding credentials or cookies during these operations in
asset-extraction.md. - [COMMAND_EXECUTION]: The skill executes local scripts and binary tools (FFmpeg, ImageMagick, Python modules) to process visual data and manage the reverse-engineering pipeline.
- Vendor patterns: Setup instructions in
session-setup.mdreference a bootstrap script athttps://raw.githubusercontent.com/voidmatcha/ui-clone-skills/main/install.sh. This is a vendor-owned resource (voidmatcha) and is documented as a manual setup step for the user rather than an automated execution by the agent.
Audit Metadata