design-system
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection because it is designed to ingest and process data from external sources and local codebase files.
- Ingestion points: The skill scans local codebase files (CSS, Tailwind, styled-components) and researches external competitor websites via the browser tool to gather design patterns.
- Boundary markers: There are no instructions or delimiters specified in the skill to prevent the agent from being influenced by malicious instructions embedded in the styling files or researched websites.
- Capability inventory: The skill utilizes file system reading, network access via a browser tool, and file system writing (generating DESIGN.md, design-tokens.json, and an interactive HTML preview).
- Sanitization: The instructions do not define any sanitization or validation steps for the content retrieved from the codebase or external URLs.
Audit Metadata