design-md-validator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npx @google/design.mdto run validation and transformation logic. This is the intended behavior for a linter and targets a well-known, official utility published by Google. - [EXTERNAL_DOWNLOADS]: The skill mentions downloading remote DESIGN.md files from URLs provided by the user before validation. This is a standard functional requirement for processing remote files and is performed to minimize risks associated with processing data directly from remote streams.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided markdown files which could theoretically contain instructions. However, the linter treats the file as structured data (YAML frontmatter and specific markdown headers), and the instructions explicitly guide the agent to interpret findings structurally rather than executing content from the file.
Audit Metadata