ui-design

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the grep utility as part of a self-audit process. This command is used to scan generated code for prohibited strings, such as forbidden color names, font families, or emojis, ensuring adherence to design specifications.
  • [EXTERNAL_DOWNLOADS]: The skill recommends incorporating assets from trusted organizations and well-known services, including professional icon libraries (FontAwesome, Heroicons, Material Icons, Feather Icons, Lucide) and media platforms (Unsplash, Pexels, Vimeo) for UI prototypes.
  • [PROMPT_INJECTION]: This skill includes strong instructional steering and identifies a potential surface for indirect prompt injection. * Ingestion points: User design requirements are processed to generate code and interface prototypes (SKILL.md). * Boundary markers: There are no explicit delimiters or instructions defined to isolate user-provided data from the agent's internal logic. * Capability inventory: The skill allows the agent to generate executable frontend code (React, Tailwind) and execute shell commands (grep) on the local filesystem (SKILL.md). * Sanitization: No input validation or filtering is specified for the user requirements before they are incorporated into the design process.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 04:37 PM