helio-ux-metrics

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a knowledge base and instructional guide. No evidence of prompt injection, data exfiltration, or malicious persistence was found.
  • [EXTERNAL_DOWNLOADS]: The skill includes a link to source documentation hosted on Google Drive. This is a reference to a well-known service used for documentation and does not present a security risk.
  • [COMMAND_EXECUTION]: The reference.md file contains a shell command example for helio-cli. This is provided for educational purposes to demonstrate the vendor's command-line interface and does not involve the execution of untrusted remote code.
  • [SAFE]: Indirect Prompt Injection analysis. The skill is designed to process user queries about UX metrics. Although it lacks explicit boundary markers for user-provided data, the skill does not have access to sensitive capabilities (such as network access or file system modifications) that could be abused through malicious input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 02:52 PM
Security Audit — agent-trust-hub — helio-ux-metrics