ds-inspection
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely within the user's project directory (
ds-inspection/folder) and does not attempt to access sensitive system paths (e.g.,.ssh,.aws,.env). - [SAFE]: Data collection is strictly limited to design system metadata (component lists, token JSON, accessibility configs) and relies on a manual fallback chain (interview/screenshots) when live tool access is unavailable.
- [SAFE]: The skill mentions external tools like 'Figma MCP' or 'Design System Ops', but it does not execute remote scripts or download unverified packages. It instructs the user on how to connect their own bridges.
- [SAFE]: There are no signs of prompt injection or attempts to bypass safety filters. The instructions focus on structured evaluation and scoring of professional assets.
- [SAFE]: The project uses local file writes for reporting and work orders, which is standard behavior for an AI agent skill and does not involve network exfiltration.
Audit Metadata