ux-evaluate
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functionality is limited to reading and writing markdown files within the designated project workspace (
.sage/work/). It does not use any tools that would allow network communication or system-level command execution. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by ingesting data from external artifacts.
- Ingestion points: Reads
.sage/work/<feature>/current-design-system.mdand.sage/work/<feature>/category-benchmarks.mdin Step 1. - Boundary markers: Absent. The instructions do not specify using delimiters to separate the loaded data from the agent's instructions.
- Capability inventory: Limited to reading local markdown files and writing a
design-evaluation.mdreport. - Sanitization: Absent. The skill does not describe any validation or escaping of the content found in the input artifacts.
Audit Metadata