stitch-ui-prompt-architect
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified in the skill. The instructions focus on improving UI prompt quality and visual specificity using established design patterns.
- [PROMPT_INJECTION]: Indirect Prompt Injection analysis: 1. Ingestion points: The skill ingests untrusted user input and processes contents from a project file (DESIGN.md) in SKILL.md. 2. Boundary markers: The skill does not define explicit delimiters or instructions to ignore potential instructions embedded in the input data. 3. Capability inventory: The skill utilizes the 'Read' tool and generates input for a downstream generation tool. 4. Sanitization: No explicit validation or filtering of external input content is described. Note: These findings describe the functional surface of the skill and do not indicate malicious intent.
- [COMMAND_EXECUTION]: The skill mentions a 'Gate rule' to re-invoke itself for quality assurance, which is a logical control flow within the agent context and does not involve shell command execution or privilege escalation.
Audit Metadata