wot-ui-v2
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use a local command-line interface tool,
wot, to query component information (e.g.,wot list,wot info,wot demo). This tool appears to be a documentation helper provided by the skill author for looking up offline knowledge. - [EXTERNAL_DOWNLOADS]: The reference documentation mentions installing the
@wot-ui/uipackage and its dependencysassvia package managers likepnpm. These are standard dependencies for projects using the wot-ui library. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes user queries to generate code and uses external reference files (
references/overview.md). However, the instructions include specific guidelines for adhering to established component patterns and API structures, which serves as a natural boundary against unexpected behavior. - Ingestion points: User queries regarding components, page scenarios, and problem descriptions (SKILL.md).
- Boundary markers: The skill emphasizes adhering to the official documentation and specific CLI outputs, reducing the likelihood of following instructions embedded within processed code snippets.
- Capability inventory: The agent is expected to execute local documentation commands (
wot) and generate code scripts for frontend development. - Sanitization: None explicitly mentioned, but the focus is on static documentation and standard library usage.
Audit Metadata