ui-design-system
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified. The skill's functionality is consistent with its stated purpose as a design utility.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local Python script,
scripts/design_token_generator.py. This is the primary intended mechanism for processing design parameters and generating token assets. - [PROMPT_INJECTION]: The skill accepts user-supplied arguments for color, style, and format, which are passed to a command-line script. This represents a potential indirect prompt injection surface, though the risk is minimal given the script's internal validation.
- Ingestion points: User-provided inputs for
brand_color,style, andformatdefined inSKILL.md. - Boundary markers: Not present in the shell command template.
- Capability inventory: Execution of local scripts via
Bashand file reading viaRead. - Sanitization: The Python script performs hex-code validation, which ensures that malformed input will cause a predictable error during processing rather than arbitrary execution.
Audit Metadata