ui-designer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill documentation and examples focus on standard UI design workflows and accessibility compliance without any malicious patterns.
  • [COMMAND_EXECUTION]: The skill correctly identifies the use of Bash for the primary task of generating design documentation and specifications.
  • [EXTERNAL_DOWNLOADS]: Reference materials mention standard, well-known packages like @axe-core/cli for accessibility testing, which are trusted industry tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes user UI requests using file-writing and shell capabilities. Ingestion point: user queries (SKILL.md). Capability inventory: Bash, Read, Write, Edit (SKILL.md). Boundary markers and sanitization methods are not defined. This surface is expected for the skill's design-generation purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — ui-designer