atai-design-system
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches design system tokens and primitives from official Archetype AI npm packages and vendor-hosted component registries on Cloudflare Workers. All external sources are verified as belonging to the skill author's infrastructure.
- [COMMAND_EXECUTION]: The agent is instructed to use
npxto execute the@archetypeai/ds-cliandshadcn-sveltetools for project initialization and component management. These commands are standard for modern web development workflows. - [REMOTE_CODE_EXECUTION]: Executing the
@latestversion of the design system CLI vianpxinvolves running remote code. This is a trusted operation as the tool is part of the vendor's official design system distribution. - [SAFE]: The skill provides explicit guidance on project security, recommending the use of
.gitignorefor commercial font files to prevent their inclusion in public repositories. - [SAFE]: The skill implements a multi-step configuration chain where the CLI installs local
CLAUDE.mdandds-manifest.jsonfiles as the project's source of truth. Ingestion points: The agent reads these files from the project root after scaffolding. Boundary markers: The skill establishes these files as the authoritative source for future component usage. Capability inventory: The agent uses manifest recipes to generate UI markup. Sanitization: None; the process relies on the established trust of the vendor-provided scaffolding tools.
Audit Metadata