5 min read

UI UX Pro Max: Design Rules Your AI Agent Can Search (GitHub, Scanned)

A design skill that gives coding agents searchable styles, palettes, font pairings and UX rules.

UI UX Pro Max logo
✅
Scan: safe. Nothing malicious in the skill or its CLI. The notes concern a demo gallery site with outdated dependencies, which you should not deploy as is, and an optional logo generator that calls paid image APIs with your own key. Scanned Oct 8, 2026; the full report is below.

UI UX Pro Max is a design skill for coding agents. Instead of leaving colour, type and layout choices to the model's taste, it ships a local database of 79 UI styles (50 active), 192 colour palettes, 74 Google Fonts pairings, 34 landing page patterns, 25 chart types, 119 UX guidelines and stack-specific advice for 22 frameworks, from React and Tailwind to SwiftUI, Flutter and Jetpack Compose. A small Python script searches those CSV and JSON files with BM25 ranking, so the agent looks up rules rather than guessing.

Its main feature is a design system generator: ask for a landing page for a spa or a fintech dashboard and the skill matches the product type against 192 industry rules, then hands the agent a pattern, style, palette, typography, effects, anti-patterns to avoid and a pre-delivery checklist covering contrast, focus states, reduced motion and responsive breakpoints. In Claude Code, Cursor, Codex and most other agents it activates on its own when you ask for UI work; a few agents use a /ui-ux-pro-max slash command instead.

The repository has about 134,000 stars and 97 contributors and is MIT-licensed. It installs through a Claude Code plugin marketplace or through its own npm CLI, ui-ux-pro-max-cli, which sets it up for more than 20 agents. The authors also sell a premium version with brand, logo and asset generation; this open repository is the free basic version.

Who it is for

Developers and founders who build interfaces with an AI agent and want more consistent, accessible results than the default purple-gradient landing page, without hiring a designer for every screen.

Getting started

1. Claude Code: add the marketplace

/plugin marketplace add nextlevelbuilder/ui-ux-pro-max-skill

2. Claude Code: install the skill

/plugin install ui-ux-pro-max@ui-ux-pro-max-skill

3. Other agents: install the CLI

npm install -g ui-ux-pro-max-cli

4. Then, in your project, pick your agent (cursor, codex, windsurf, gemini and more)

uipro init --ai cursor

The /plugin commands are typed inside Claude Code, not a shell. The search script needs Python 3, standard library only. The npm package is ui-ux-pro-max-cli; the README says the older uipro-cli releases are stale and should not be used.

Safety scan

We cloned nextlevelbuilder/ui-ux-pro-max-skill at commit 1a2c459 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns and no committed binaries across 681 files. A second, skill-specific pass for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths and pipe-to-shell commands found nothing malicious.
  • The CLI in cli/ only talks to api.github.com and github.com, to download the project's own release zips, and its lockfile has no known advisories. The core search script reads local data files and makes no network calls.
  • All 45 known advisories (2 critical, 21 high) are in gallery/package-lock.json, a demo style-gallery website pinned to Next.js 14.2, including Next.js remote code execution advisories. The skill never uses it; it only matters if you run or deploy that gallery yourself, and you should not deploy it without upgrading Next.js first.
  • The optional design skill includes logo, icon and corporate-identity generators (scripts/logo/generate.py and siblings) that call Google Gemini by default, or Atlas Cloud or MuAPI if you choose, using API keys you put in your own environment. They only run when you invoke them, and each image request is billed to you.
  • Six workflows, none using pull_request_target. Security policy, licence, contributing guide and code of conduct present; no Dependabot or CodeQL. The one setup script, stack/scripts/setup.sh, is 32 lines that run npm install, Playwright's Chromium download and the project's own CLI, without sudo.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 installer script
Committed binariesNone.
CI workflows6 workflows. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit.
Network hosts15 distinct hosts referenced from source; most often images.pexels.com, github.com, api.muapi.ai, media.example.com. No URLs to bare IP addresses.
Known vulnerabilities45 advisories across 144 pinned packages: 2 critical, 21 high, 19 moderate, 3 low. cli/package-lock.json: 32 packages, 0 advisories; gallery/package-lock.json: 115 packages, 45 advisories.
Project hygieneHas security policy, licence file, contributing guide. Missing automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Installer scripts (1)
Worst known vulnerabilities (24 of 45)
AdvisorySeverityPackageSummary
GHSA-2xp9-vwfh-vxw4criticalnext@14.2.35Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-p293-qw3h-jr36criticalnext@14.2.35Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-73wf-gq98-2v4ghighbrowserslist@4.28.1Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
GHSA-c83g-rgw3-j3cxhighbrowserslist@4.28.1Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
GHSA-28wg-ghj8-5hjvhighnanoid@3.3.11nanoid: non-secure generators can loop indefinitely with negative size
GHSA-2v37-7h3g-55p8highnanoid@3.3.11nanoid: custom generators can loop indefinitely when size is zero
GHSA-xwg4-73v4-xw9whighnanoid@3.3.11nanoid: Integer Overflow or Wraparound
GHSA-36qx-fr4f-26g5highnext@14.2.35Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
GHSA-89xv-2m56-2m9xhighnext@14.2.35Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-8h8q-6873-q5fjhighnext@14.2.35Next.js Vulnerable to Denial of Service with Server Components
GHSA-c4j6-fc7j-m34rhighnext@14.2.35Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
GHSA-h25m-26qc-wcjfhighnext@14.2.35Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
GHSA-m99w-x7hq-7vfjhighnext@14.2.35Next.js: Denial of Service in App Router using Server Actions
GHSA-p9j2-gv94-2wf4highnext@14.2.35Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-q4gf-8mx6-v5v3highnext@14.2.35Next.js has a Denial of Service with Server Components
GHSA-6g55-p6wh-862qhighpostcss@8.4.31PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-r28c-9q8g-f849highpostcss@8.4.31PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-c2c7-rcm5-vvqjhighpicomatch@2.3.1Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-6g55-p6wh-862qhighpostcss@8.5.6PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-r28c-9q8g-f849highpostcss@8.5.6PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-68fv-2mgg-jv7qhighsource-map-js@1.2.1source-map-js allows event-loop denial of service through indexed source-map section offsets
GHSA-c2c7-rcm5-vvqjhighpicomatch@4.0.3Picomatch has a ReDoS vulnerability via extglob quantifiers
GHSA-w5vr-8v7q-w6rvmoderatebaseline-browser-mapping@2.9.19baseline-browser-mapping process termination on invalid input causes denial of service

By the numbers

Stars134K
Forks14.2K
Contributors97
Commits271
Open issues41
Open pull requests46
Releases41
Latest releasev2.15.0
LicenceMIT
Main languagePython
Project age10 months
Last pushOct 8, 2026
Tracked files681
Lines of code251K
Checkout size22 MB

Lines by language: JSON 175.4K, Python 36.2K, Markdown 27.9K, JavaScript 4,599, TypeScript 4,347, HTML 1,627.

Questions

Is UI UX Pro Max free?

Yes. This repository is MIT-licensed and free, and the skill runs locally with Python 3. You still need a coding agent such as Claude Code, Cursor or Codex under its own pricing. The authors sell a separate premium version with brand identity, logo and asset generation, which you do not need for the features described here.

Does it send my project anywhere?

No. The skill searches local CSV and JSON files and the README states the search script makes no network calls. The CLI downloads release files from GitHub when installing. Only the optional logo and image generators contact outside services, and only with an API key you supply.

Which agents does it support?

Claude Code through the plugin marketplace, and through the uipro CLI more than 20 others, including Cursor, Windsurf, Codex, Gemini CLI, GitHub Copilot, Kiro, Roo Code, OpenCode, Continue and Trae, plus a universal .agents/skills/ install for any agent that reads the Agent Skills format.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.