design-system
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a browser tool to visit external websites for design inspiration and to perform visual audits on user-provided URLs, which involves network requests to non-whitelisted domains.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted content from local styling files and external web pages.
- [INGESTION_POINTS]: Local CSS, Tailwind, and styled-components files, as well as remote URLs provided during the audit mode.
- [BOUNDARY_MARKERS]: No markers or instructions are provided to the agent to ignore potentially malicious embedded content within the analyzed files or pages.
- [CAPABILITY_INVENTORY]: The skill requires filesystem read/write access (to scan for patterns and generate design tokens/previews) and browser tool usage.
- [SANITIZATION]: The skill instructions do not specify any validation or sanitization steps for the data ingested from external sources.
Audit Metadata