design-system
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by processing untrusted data from external sources and local files without clear isolation.
- Ingestion points: The skill reads local source code (CSS, Tailwind, styled-components) and visits external competitor websites using a browser tool.
- Boundary markers: There are no instructions or delimiters specified to prevent the agent from following commands embedded in the files or websites it analyzes.
- Capability inventory: The skill utilizes tools for file system reading, file system writing (generating DESIGN.md, tokens, and HTML previews), and network access (web browsing).
- Sanitization: The skill lacks explicit sanitization or filtering of the content retrieved from external websites or local code before it is processed by the agent.
Audit Metadata