design-system-generator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill demonstrates safe behavior throughout its files. No signs of obfuscation, hardcoded credentials, unauthorized network operations, or malicious intent were found during the analysis.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided natural language descriptions to generate design systems, creating a standard interaction surface.
- Ingestion points: Descriptions are ingested as command-line arguments by
scripts/match-trend.tsto identify design trends. - Boundary markers: None are explicitly used to separate user input from internal instructions.
- Capability inventory: The skill generates design tokens, CSS variables, and Tailwind configurations based on the analysis.
- Sanitization: Input strings are processed for keyword matching and score calculation within the script's logic, without being passed to a shell or dynamic evaluator.
- [COMMAND_EXECUTION]: The skill uses local TypeScript scripts (
scripts/*.ts) to handle trend matching and code generation. These scripts are intended to be executed viats-nodeas part of the primary workflow and do not exhibit dangerous command injection patterns or elevated privilege requirements. - [DATA_EXPOSURE]: The generator scripts reference a design catalog file at a hardcoded relative path (
../../../../website/design-catalog/gallery-sources.json). This appears to be a functional dependency on the vendor's internal project structure rather than an attempt to access sensitive system files.
Audit Metadata