helio-ux-metrics
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a knowledge base and instructional guide. No evidence of prompt injection, data exfiltration, or malicious persistence was found.
- [EXTERNAL_DOWNLOADS]: The skill includes a link to source documentation hosted on Google Drive. This is a reference to a well-known service used for documentation and does not present a security risk.
- [COMMAND_EXECUTION]: The
reference.mdfile contains a shell command example forhelio-cli. This is provided for educational purposes to demonstrate the vendor's command-line interface and does not involve the execution of untrusted remote code. - [SAFE]: Indirect Prompt Injection analysis. The skill is designed to process user queries about UX metrics. Although it lacks explicit boundary markers for user-provided data, the skill does not have access to sensitive capabilities (such as network access or file system modifications) that could be abused through malicious input.
Audit Metadata