design-system

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and associated templates are focused on legitimate development tasks including token extraction and component generation. No malicious patterns such as obfuscation, exfiltration, or unauthorized remote execution were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data from design files and brand guides.
  • Ingestion points: Figma URLs and design documents specified in the Inputs section of SKILL.md.
  • Boundary markers: Explicit constraints against silent fabrication ('Never fabricate a whole design system silently') and mandatory user verification steps ('Never claim the design system verified until they have looked') are enforced in SKILL.md.
  • Capability inventory: File system access to write components, tokens, and registration documentation, as well as the ability to generate new project-specific agent skills.
  • Sanitization: Risk is mitigated through required manual inspection of generated preview pages and explicit phase updates for user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 06:26 PM
Security Audit — agent-trust-hub — design-system