design-system
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill performs standard design-related tasks such as file scanning and web research.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests untrusted data from external websites for competitive research.
- Ingestion points: Competitive research via browser MCP (SKILL.md).
- Boundary markers: Absent; there are no explicit instructions to the agent to ignore embedded commands in the external data.
- Capability inventory: File writing (DESIGN.md, design-tokens.json, design-preview.html).
- Sanitization: Absent; the skill does not specify filtering or validation of the content retrieved from external URLs.
Audit Metadata