skills/xoai/sage/ux-evaluate/Gen Agent Trust Hub

ux-evaluate

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is limited to reading and writing markdown files within the designated project workspace (.sage/work/). It does not use any tools that would allow network communication or system-level command execution.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting data from external artifacts.
  • Ingestion points: Reads .sage/work/<feature>/current-design-system.md and .sage/work/<feature>/category-benchmarks.md in Step 1.
  • Boundary markers: Absent. The instructions do not specify using delimiters to separate the loaded data from the agent's instructions.
  • Capability inventory: Limited to reading local markdown files and writing a design-evaluation.md report.
  • Sanitization: Absent. The skill does not describe any validation or escaping of the content found in the input artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 01:31 AM
Security Audit — agent-trust-hub — ux-evaluate