design-sync

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill facilitates the synchronization of design files (CSS, HTML, MD) to claude.ai/design, which is a well-known and trusted service associated with the agent's platform.
  • [DATA_EXFILTRATION]: The skill uses specific tools to upload local design system files to a remote project. This behavior is consistent with the stated primary purpose of the skill and targets a recognized service.
  • [PROMPT_INJECTION]: The skill addresses the risk of indirect prompt injection by explicitly instructing the agent to treat content retrieved from remote files as data rather than instructions. This is a recommended safety practice when processing shared or external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 05:49 PM
Security Audit — agent-trust-hub — design-sync