design-engineering
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing official and well-known MCP servers and SDKs from trusted providers including Google Labs (
@google/stitch-sdk,google-labs-code/stitch-skills) and Figma (figma-developer-mcp). These references are consistent with the skill's primary purpose and target well-known services. - [COMMAND_EXECUTION]: Shell commands included in the documentation are for legitimate setup purposes, such as adding MCP servers to the agent environment (
claude mcp add) or initializing project dependencies. These commands utilize placeholders (e.g.,YOUR_KEY) and follow standard security practices for secret management. - [SAFE]: The skill demonstrates a strong commitment to security and quality by providing detailed guidelines for accessibility (WCAG 2.2 AA) and visual validation workflows. It does not contain any prompt injection attempts, data exfiltration patterns, or obfuscated content.
Audit Metadata