skills/biasia/c2d2c/restore/Gen Agent Trust Hub

restore

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local tools such as node for a screenshot script (ds-shot.mjs) and the glab CLI for merge request management. These are standard operations for a development automation tool.
  • [PROMPT_INJECTION]: The skill identifies as a surface for indirect prompt injection due to its ingestion of external Figma design data and variables. Ingestion points: Figma design context and variable definitions. Boundary markers: None present in the instructions. Capability inventory: Shell command execution via node and glab, and file system write access. Sanitization: No explicit data sanitization steps are documented.
  • [SAFE]: Human-in-the-loop checkpoints are established for plan approval, style verification, and final acceptance, mitigating the risks of automated execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 11:08 AM
Security Audit — agent-trust-hub — restore