design-system

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection because it is designed to ingest and process data from external sources and local codebase files.
  • Ingestion points: The skill scans local codebase files (CSS, Tailwind, styled-components) and researches external competitor websites via the browser tool to gather design patterns.
  • Boundary markers: There are no instructions or delimiters specified in the skill to prevent the agent from being influenced by malicious instructions embedded in the styling files or researched websites.
  • Capability inventory: The skill utilizes file system reading, network access via a browser tool, and file system writing (generating DESIGN.md, design-tokens.json, and an interactive HTML preview).
  • Sanitization: The instructions do not define any sanitization or validation steps for the content retrieved from the codebase or external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — design-system