hiui-design
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a robust set of instructions and templates for UI generation. All identified patterns are consistent with its stated purpose as a design system utility.
- [COMMAND_EXECUTION]: The skill instructions (SKILL.md) guide the agent to run a local script (
scripts/plan-page-task.mjs) to generate task plans. This is a legitimate use case for a development-oriented AI agent skill and does not involve high-risk arbitrary command execution or privilege escalation. - [DATA_EXFILTRATION]: No patterns of data exfiltration were found. The skill does not perform unauthorized network requests or access sensitive local files (e.g., SSH keys, AWS credentials).
- [PROMPT_INJECTION]: The instructions do not contain malicious overrides, role-play jailbreaks, or attempts to bypass safety filters. It maintains a strictly technical and instructional tone.
- [EXTERNAL_DOWNLOADS]: Dependencies listed in the
package.jsonfiles are standard packages from the official NPM registry belonging to the@hi-uiand@hiui-designnamespaces, which are consistent with the skill's authorship.
Audit Metadata