cds-code
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The README.md file recommends the installation of official companion skills, such as
cds-docsfrom the Coinbase GitHub repository andskill-creatorfrom the Anthropics repository. These are documented references to trusted external resources. - [DYNAMIC_EXECUTION]: The skill includes several scripts (
discover-cds-packages.sh,discover-cds-icons.mjs,discover-cds-illustrations.mjs) used to identify the installed version and assets of the Coinbase Design System in a user's project. These scripts utilize dynamic execution patterns, including the use ofnode -eto parse package metadata and dynamicimport()to load icon and illustration data from the localnode_modulesdirectory at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill's code review workflow (
guidelines/code-review.md) involves the agent ingesting and auditing up to 50 local source files. This creates a surface for indirect prompt injection where instructions embedded in code comments or strings could potentially influence the agent's output. - Ingestion points: Local source code files provided by the user for CDS adherence audits.
- Boundary markers: None present; the skill processes the files directly.
- Capability inventory: The skill can execute local discovery scripts and perform file system read/write operations within the project context.
- Sanitization: No specific sanitization or filtering of the ingested source code is performed before the audit.
Audit Metadata