create-design-system

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill mentions downloading fonts from Google Fonts and linking to icon CDNs like Lucide or Heroicons. These are well-known services and the downloads are limited to static assets (fonts/icons), which is a standard development practice.
  • [DYNAMIC_EXECUTION]: The skill generates HTML specimen cards that mount React components using a script tag with a Babel compiler. This is a common pattern for runtime previews of design system components in development environments.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions direct the agent to explore local codebases, Figma design contexts, and slide decks to extract branding info. While this involves accessing potentially sensitive design assets, it is the primary intended function of the skill and does not involve exfiltration to unknown domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Figma links and project codebases. This creates a surface for indirect instructions, though the risk is inherent to the task of asset analysis. 1. Ingestion points: Figma design data, project codebases, and attached slide deck files. 2. Boundary markers: No specific boundary markers are defined for the analyzed external content. 3. Capability inventory: The skill allows for file read/write, REPL execution for asset extraction, and platform-specific tool calls. 4. Sanitization: There is no explicit requirement for sanitizing input from external design sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 12:42 PM
Security Audit — agent-trust-hub — create-design-system