design-system
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional markdown and configuration files aimed at design system governance. It does not contain executable code, remote dependencies, or suspicious commands.
- [PROMPT_INJECTION]: The instructions are focused on architectural classification and decision-making for UI systems. No patterns for bypassing safety filters, overriding system prompts, or role-play injections were identified.
- [DATA_EXFILTRATION]: The skill does not access sensitive files (e.g., credentials, SSH keys) or perform network operations to external domains. The
allowed-tools(Bash, Read, Write, Edit, Glob, Grep) are standard for project file management. - [REMOTE_CODE_EXECUTION]: There is no evidence of remote script execution, dynamic code loading, or installation of untrusted packages.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests user requirements and operates on project files using standard filesystem tools. However, its primary function is generating documentation (Design System Packets) and providing architectural guidance rather than executing data-driven logic. No specific sanitization or boundary markers are defined for external input, but the risk is negligible given the intended use case. (Severity: LOW).
Audit Metadata