ui-design-system

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified. The skill's functionality is consistent with its stated purpose as a design utility.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local Python script, scripts/design_token_generator.py. This is the primary intended mechanism for processing design parameters and generating token assets.
  • [PROMPT_INJECTION]: The skill accepts user-supplied arguments for color, style, and format, which are passed to a command-line script. This represents a potential indirect prompt injection surface, though the risk is minimal given the script's internal validation.
  • Ingestion points: User-provided inputs for brand_color, style, and format defined in SKILL.md.
  • Boundary markers: Not present in the shell command template.
  • Capability inventory: Execution of local scripts via Bash and file reading via Read.
  • Sanitization: The Python script performs hex-code validation, which ensures that malformed input will cause a predictable error during processing rather than arbitrary execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — ui-design-system