design
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/verify.shscript executes shell commands includingcurl,grep,ripgrep, andnpx. These are used for project auditing and verifying local server status. Additionally,references/starting-point.mdinstructs the execution ofnpx @ericrisco/rsc doctorto check project state. Bothlighthouseand the vendor-specificdoctortool are used for legitimate diagnostic purposes. - [EXTERNAL_DOWNLOADS]: The skill references several external resources and packages.
references/design-systems.mdsuggests installing official design system packages such as@shopify/polarisandgovuk-frontend.scripts/verify.shusesnpxto runlighthouse, a well-known performance auditing tool. These references target trusted or well-known organizations. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from untrusted or external sources, including project documentation and web pages fetched during research.
- Ingestion points: Reads local files like
CLAUDE.mdand02-DOCS/wiki/brand/to establish design context. UsesWebFetchinreferences/research-method.mdto analyze external inspiration sites. - Boundary markers: The instructions provide specific templates for data extraction, which limits the scope of processed input.
- Capability inventory: Includes file system writes and shell command execution for performance auditing.
- Sanitization: No explicit sanitization or delimiter-based escaping is defined for external web content before synthesis.
Audit Metadata