skills/coinbase/cds/cds-code/Gen Agent Trust Hub

cds-code

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The README.md file recommends the installation of official companion skills, such as cds-docs from the Coinbase GitHub repository and skill-creator from the Anthropics repository. These are documented references to trusted external resources.
  • [DYNAMIC_EXECUTION]: The skill includes several scripts (discover-cds-packages.sh, discover-cds-icons.mjs, discover-cds-illustrations.mjs) used to identify the installed version and assets of the Coinbase Design System in a user's project. These scripts utilize dynamic execution patterns, including the use of node -e to parse package metadata and dynamic import() to load icon and illustration data from the local node_modules directory at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill's code review workflow (guidelines/code-review.md) involves the agent ingesting and auditing up to 50 local source files. This creates a surface for indirect prompt injection where instructions embedded in code comments or strings could potentially influence the agent's output.
  • Ingestion points: Local source code files provided by the user for CDS adherence audits.
  • Boundary markers: None present; the skill processes the files directly.
  • Capability inventory: The skill can execute local discovery scripts and perform file system read/write operations within the project context.
  • Sanitization: No specific sanitization or filtering of the ingested source code is performed before the audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:37 PM
Security Audit — agent-trust-hub — cds-code