refero-design

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown documentation and design guidelines. No scripts, binaries, or malicious patterns were detected across the analyzed files.
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of the Refero MCP server at api.refero.design to fetch design references. This is a primary feature of the skill, and the domain is associated with the author ('bbssppllvv').
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices for credential management by instructing users to provide their own authentication tokens via standard MCP headers, using placeholders like <token> instead of hardcoded secrets.
  • [COMMAND_EXECUTION]: The README provides standard setup commands for users to configure the skill and MCP server (e.g., claude mcp add, npx skills add), which are intended for initial configuration and not for automated execution by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 08:35 AM
Security Audit — agent-trust-hub — refero-design