gsd-ui-phase

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a coordinator for a structured UI design process, relying on local project-specific workflows and internal agent collaboration.\n- [COMMAND_EXECUTION]: The skill uses spawn_agent to delegate tasks to gsd-ui-researcher and gsd-ui-checker. This behavior is standard for the orchestration of multi-agent workflows.\n- [DATA_EXFILTRATION]: The skill accesses local reference files and workflow definitions located in /mnt/local-analysis/workspace-hub/. This access is confined to the expected local workspace environment for the tool.\n- [PROMPT_INJECTION]: The skill processes user-provided arguments and local workflow files to guide its operations.\n
  • Ingestion points: {{GSD_ARGS}} in SKILL.md and the ui-phase.md workflow file.\n
  • Boundary markers: Absent.\n
  • Capability inventory: spawn_agent, request_user_input.\n
  • Sanitization: Not implemented. Although this represents a surface for indirect prompt injection, the risk is minimized by the skill's specific focus on localized project workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 01:04 PM