{"data":{"skill":{"slug":"zhanlincui-ui-ux-pro-max","name":"ui-ux-pro-max","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/ui-ux-pro-max","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"3acc1233-8b0d-4b85-8f49-a78d87b0b7e9","skill_id":"2e174dbb-23e7-4f4b-994f-b892eae1ac13","version":2,"content_hash":"3b94aae56fc8cc8b08e9274db153f3fc","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis produced many high and critical alerts, but review shows most are false positives from UI guidance text, CSV examples, documentation URLs, and command snippets. No prompt-injection text, credential exfiltration, network beaconing, or malicious command execution was confirmed. The real concern is a local persistence feature that writes markdown files using user-controlled output directory, project, and page names, so publication should include a filesystem warning.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"scripts/search.py","line_end":75,"line_start":66},{"file":"scripts/design_system.py","line_end":482,"line_start":461}]},{"factor":"filesystem","evidence":[{"file":"scripts/design_system.py","line_end":530,"line_start":503},{"file":"scripts/search.py","line_end":62,"line_start":60}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":117,"line_start":104}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"User-Controlled Design-System File Writes","locations":[{"file":"scripts/search.py","line_end":75,"line_start":60},{"file":"scripts/design_system.py","line_end":530,"line_start":503}],"confidence":0.78,"description":"The CLI accepts --output-dir and --page, then persist_design_system builds paths and writes MASTER.md plus optional page markdown files. This appears intended and requires the user to run the persist option, but project and page names are only lightly transformed and can influence local write paths.","confidence_reasoning":"The file writes are directly confirmed in the script, and their destination is influenced by CLI arguments and generated project names. Risk is moderate because writes are local markdown persistence, not hidden execution or exfiltration."}],"low_findings":[{"title":"Static Network and Secret Findings Are Guideline Examples","locations":[{"file":"data/stacks/nextjs.csv","line_end":38,"line_start":35},{"file":"data/stacks/nuxtjs.csv","line_end":55,"line_start":52},{"file":"data/react-performance.csv","line_end":4,"line_start":2}],"confidence":0.9,"description":"Fetch calls, process.env references, .env mentions, API secret labels, and documentation URLs appear inside framework guidance CSV rows. They describe recommended and discouraged application patterns rather than code executed by this skill.","confidence_reasoning":"The cited lines are CSV guidance records with Do and Do not columns, not executable code paths. This strongly supports a false-positive assessment for those static findings."},{"title":"Keylogger and Reconnaissance Alerts Are Text-Match False Positives","locations":[{"file":"data/stacks/react.csv","line_end":30,"line_start":28},{"file":"data/stacks/react-native.csv","line_end":51,"line_start":49},{"file":"data/stacks/nuxt-ui.csv","line_end":17,"line_start":16}],"confidence":0.88,"description":"Keylogger-related alerts map to phrases such as every keystroke, input handlers, hook rules, and testing guidance. No evidence found of key capture, surveillance logic, or system reconnaissance behavior.","confidence_reasoning":"The suspicious words are embedded in ordinary UX and framework examples. I did not find code that registers global keyboard capture or transmits input data."},{"title":"Installer Command Snippets Require User Action","locations":[{"file":"SKILL.md","line_end":117,"line_start":104}],"confidence":0.86,"description":"The skill documentation includes brew, sudo apt, and winget installation commands for Python prerequisites. These are visible setup instructions, not automatic command execution by the skill.","confidence_reasoning":"The commands are fenced documentation examples and there is no script path that runs them automatically. They still merit low-risk disclosure because sudo is suggested to users."},{"title":"Prompt Injection Review Found No Evidence","locations":[{"file":"SKILL.md","line_end":13,"line_start":1}],"confidence":0.82,"description":"Targeted review did not find instructions claiming special authority, telling the auditor to ignore prior instructions, or asking to skip security analysis. No evidence found of prompt-injection attempts in the reviewed files.","confidence_reasoning":"The reviewed skill header and guidance describe UI/UX behavior without attempting to override evaluator instructions. Confidence is high but not absolute because only targeted review was performed."}],"dangerous_patterns":[{"title":"User-Controlled Design-System File Writes","locations":[{"file":"scripts/search.py","line_end":75,"line_start":60},{"file":"scripts/design_system.py","line_end":530,"line_start":503}],"confidence":0.78,"description":"The CLI accepts --output-dir and --page, then persist_design_system builds paths and writes MASTER.md plus optional page markdown files. This appears intended and requires the user to run the persist option, but project and page names are only lightly transformed and can influence local write paths.","confidence_reasoning":"The file writes are directly confirmed in the script, and their destination is influenced by CLI arguments and generated project names. Risk is moderate because writes are local markdown persistence, not hidden execution or exfiltration."}],"files_scanned":28,"total_lines":3254,"audit_model":"codex","audited_at":"2026-07-01T03:41:12.859+00:00","created_at":"2026-07-01T04:01:07.176538+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}