design-sync
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill facilitates the synchronization of design files (CSS, HTML, MD) to
claude.ai/design, which is a well-known and trusted service associated with the agent's platform. - [DATA_EXFILTRATION]: The skill uses specific tools to upload local design system files to a remote project. This behavior is consistent with the stated primary purpose of the skill and targets a recognized service.
- [PROMPT_INJECTION]: The skill addresses the risk of indirect prompt injection by explicitly instructing the agent to treat content retrieved from remote files as data rather than instructions. This is a recommended safety practice when processing shared or external content.
Audit Metadata