skills/zeroz-lab/gm-skills/ui-fork/Gen Agent Trust Hub

ui-fork

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes file system tools including Read, Write, and Edit to manage the DESIGN.md document. This behavior is necessary for extracting and persisting design system data from UI screenshots.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted external data. Ingestion points: UI screenshots and product background text entering the agent context via input parameters defined in SKILL.md. Boundary markers: Absent. Capability inventory: Read, Write, and Edit tool calls defined in SKILL.md for modifying the local file system. Sanitization: Absent; no validation or escaping of the ingested visual or textual content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 02:35 PM