design-system-documenter
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill consists entirely of Markdown instructions and documentation templates. It does not include any scripts or executable code.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external design token files (JSON or CSS formats) to generate documentation. While this is an ingestion point for untrusted content, the risk is minimized by the skill's rigid documentation templates and lack of active code execution. 1. Ingestion points: Reads generated tokens.json or CSS variables files. 2. Boundary markers: None explicitly defined, but the output is restricted to predefined table and guideline formats. 3. Capability inventory: Uses Read, Write, and Glob tools for file manipulation; no network or execution capabilities are invoked. 4. Sanitization: Not explicitly mentioned, but the process is a static transformation into Markdown.
- [EXTERNAL_DOWNLOADS]: The skill provides reference links to several well-known design systems (e.g., Elastic UI, Red Hat PatternFly, shadcn/ui) as best practice examples. These are established, legitimate services used for design inspiration and documentation standards.
Audit Metadata