studio-design-design-system-from-code

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the user's codebase, including CSS, JavaScript, and configuration files, to identify design tokens. This represents an ingestion point for potentially malicious instructions hidden in code comments or metadata that could influence the agent's behavior during the audit.
  • Ingestion points: Reads various source code files (Tailwind configs, theme files, CSS, component implementations) within the repository.
  • Boundary markers: The instructions do not define specific delimiters or security constraints for separating code logic from data during the extraction process.
  • Capability inventory: The skill has the capability to read files in the repository and write to docs/DESIGN.md.
  • Sanitization: There are no explicit steps provided for sanitizing or filtering external code content before it is processed or written to the final documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:33 PM
Security Audit — agent-trust-hub — studio-design-design-system-from-code