design-system

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses a browser tool to visit external websites for design inspiration and to perform visual audits on user-provided URLs, which involves network requests to non-whitelisted domains.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted content from local styling files and external web pages.
  • [INGESTION_POINTS]: Local CSS, Tailwind, and styled-components files, as well as remote URLs provided during the audit mode.
  • [BOUNDARY_MARKERS]: No markers or instructions are provided to the agent to ignore potentially malicious embedded content within the analyzed files or pages.
  • [CAPABILITY_INVENTORY]: The skill requires filesystem read/write access (to scan for patterns and generate design tokens/previews) and browser tool usage.
  • [SANITIZATION]: The skill instructions do not specify any validation or sanitization steps for the data ingested from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — design-system