frontend-ui-ux-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and transform functional React components provided by a user. This processing of external data creates a potential surface for indirect prompt injection, where malicious instructions could be hidden in the input code to influence the agent's behavior.
- Ingestion points: The functional React component code provided in 'Workflow 1: Transform Functional Component to Stunning UI' (SKILL.md).
- Boundary markers: The skill does not explicitly instruct the agent to ignore or delimit instructions embedded within the input component code.
- Capability inventory: The skill focus is on code generation and visual styling; no subprocess calls, network operations, or file system write capabilities are defined within the skill's own logic.
- Sanitization: No specific sanitization or validation of the input code is implemented.
Audit Metadata