design-auditor
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill's behavior is consistent with its stated purpose of auditing designs. The following security-positive patterns were observed:
- [CONTROLLED_CAPABILITIES]: Destructive or write-heavy operations, such as
perform_editing_operationsin Figma orcreate_design_system_rulesfor repositories, are protected by mandatory user confirmation steps (Step 4 and Step 5.5). - [CREDENTIAL_HANDLING]: The instructions explicitly forbid the agent from repeating or storing user-provided credentials used to access authenticated URLs (Step 1
- URL Input Spec).
- [TRUSTED_SOURCES]: External data fetching via
web_fetchfor GitHub source code targets well-known and trusted domains (e.g.,raw.githubusercontent.com). - [TRANSPARENCY]: The skill maintains clear communication with the user regarding inferred settings, detected frameworks, and confidence levels based on input types.
Audit Metadata