skills/wot-ui/open-wot/wot-ui-v2/Gen Agent Trust Hub

wot-ui-v2

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use a local command-line interface tool, wot, to query component information (e.g., wot list, wot info, wot demo). This tool appears to be a documentation helper provided by the skill author for looking up offline knowledge.
  • [EXTERNAL_DOWNLOADS]: The reference documentation mentions installing the @wot-ui/ui package and its dependency sass via package managers like pnpm. These are standard dependencies for projects using the wot-ui library.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes user queries to generate code and uses external reference files (references/overview.md). However, the instructions include specific guidelines for adhering to established component patterns and API structures, which serves as a natural boundary against unexpected behavior.
  • Ingestion points: User queries regarding components, page scenarios, and problem descriptions (SKILL.md).
  • Boundary markers: The skill emphasizes adhering to the official documentation and specific CLI outputs, reducing the likelihood of following instructions embedded within processed code snippets.
  • Capability inventory: The agent is expected to execute local documentation commands (wot) and generate code scripts for frontend development.
  • Sanitization: None explicitly mentioned, but the focus is on static documentation and standard library usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 AM
Security Audit — agent-trust-hub — wot-ui-v2