skills/ericrisco/rsc-harness/design/Gen Agent Trust Hub

design

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/verify.sh script executes shell commands including curl, grep, ripgrep, and npx. These are used for project auditing and verifying local server status. Additionally, references/starting-point.md instructs the execution of npx @ericrisco/rsc doctor to check project state. Both lighthouse and the vendor-specific doctor tool are used for legitimate diagnostic purposes.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources and packages. references/design-systems.md suggests installing official design system packages such as @shopify/polaris and govuk-frontend. scripts/verify.sh uses npx to run lighthouse, a well-known performance auditing tool. These references target trusted or well-known organizations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from untrusted or external sources, including project documentation and web pages fetched during research.
  • Ingestion points: Reads local files like CLAUDE.md and 02-DOCS/wiki/brand/ to establish design context. Uses WebFetch in references/research-method.md to analyze external inspiration sites.
  • Boundary markers: The instructions provide specific templates for data extraction, which limits the scope of processed input.
  • Capability inventory: Includes file system writes and shell command execution for performance auditing.
  • Sanitization: No explicit sanitization or delimiter-based escaping is defined for external web content before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — design