ui-test
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md raises transparency concerns due to obfuscated or encoded execution paths and dense payload-like content, which meaningfully weaken a reviewer's ability to assess what the skill actually does before loading it. While the scan did not find strong prompt-injection patterns or clear attempts to blur instruction/data boundaries, the low confidence and lack of behavior analysis mean it's hard to confirm the skill doesn't materially change downstream behavior compared to a no-skill baseline. The WARNING verdict reflects that the skill cannot be confidently cleared: finite testing passed on injection risk, but the transparency issues make it difficult to fully rule out hidden influence on agent behavior.
The skill has 2 transparency concerns that weaken pre-use reviewability, mainly around obfuscated or encoded execution path and hidden or dense payload-like content.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Obfuscated or encoded execution path
Hidden or dense payload-like content