ui-ux-pro-max
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a local search engine (BM25) to query UI/UX guidelines and design patterns stored in CSV and JSON files within the skill's data directory. No external network requests are performed by the core logic.
- [SAFE]: The persistence logic in
scripts/design_system.pyincludes asafe_slugfunction that strictly sanitizes user-provided project and page names. This prevents path traversal attacks by collapsing any potentially dangerous characters (like '../') into hyphens. - [SAFE]: The skill uses
subprocess.runandsubprocess.Popenexclusively within its unit test suite (scripts/tests/) to verify CLI argument handling. These calls are limited to executing the skill's own search script using the system's Python interpreter. - [SAFE]: No use of dangerous functions such as
eval(),exec(), orpickle.load()was found in the codebase. Data parsing is handled via standardjson.loads()andcsv.DictReader(). - [SAFE]: References to external resources (such as Angular, React, and Google Fonts documentation) point to well-known, official domains. No hardcoded credentials or data exfiltration patterns were detected.
Audit Metadata