ui-bridge

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected across any of the analyzed files or subskills.- [COMMAND_EXECUTION]: The skill uses Python's subprocess module to orchestrate its multi-stage workflow, running internal scripts for design inference, page mapping, and artifact validation. These calls use specific script paths within the skill directory and do not involve unsanitized shell execution.- [EXTERNAL_DOWNLOADS]: Fetches assets from reputable and well-known services, including Google Fonts for typography and Unsplash for photography. These references are used solely for generating realistic prototype content.- [EXTERNAL_DOWNLOADS]: The installation process utilizes npx to fetch and install the 'impeccable' design quality tool, which is a standard part of the skill's validation architecture.- [COMMAND_EXECUTION]: Includes a local development server ('server.py') within the canvas app to support local file serving and saving of prototype layout states via JSON POST requests. Access is restricted to the local environment and its own subdirectory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 02:02 PM
Security Audit — agent-trust-hub — ui-bridge