skills/xoai/sage/ux-heuristic-review/Gen Agent Trust Hub

ux-heuristic-review

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted content such as implementation code, UX requirements, and specifications, which introduces a surface for indirect prompt injection. Malicious instructions embedded in these inputs could attempt to manipulate the assessment results.
  • Ingestion points: SKILL.md defines implementation, ux-requirements, and specification as inputs.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to isolate user-provided data from the agent's instructions.
  • Capability inventory: The skill does not contain its own scripts or tools, but the underlying agent environment typically provides file system and shell access that could be targeted via injection.
  • Sanitization: No sanitization or input validation logic is present in the skill definition.
  • [NO_CODE]: The skill is composed entirely of markdown guidelines and configuration metadata. The absence of executable scripts (Python, Node.js, or Shell) significantly limits the direct technical attack surface for vulnerabilities like remote code execution or credential theft.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 01:32 AM
Security Audit — agent-trust-hub — ux-heuristic-review