design-system

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for documentation and code alignment of design tokens. It reads local files like DIRECTION.md and BRAND.md to inform its proposals, which are then reviewed by the user.
  • [PROMPT_INJECTION]: The skill ingests data from local project files (DIRECTION.md, BRAND.md, docs/agents/stack.md in SKILL.md) without explicit boundary markers or sanitization. However, capabilities are limited to file-write operations for design tokens and CSS variables, and all changes require user confirmation, mitigating the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 07:14 AM
Security Audit — agent-trust-hub — design-system