opendesign-components

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions require the installation of the @opensig/opendesign and @opensig/opendesign-token packages from public NPM/PNPM registries.
  • [PROMPT_INJECTION]: The skill establishes an ingestion surface for indirect prompt injection (Category 8) through its integration with design data.
  • Ingestion points: Pixso MCP design node metadata, including layer names, visual attributes, and layout structures (defined in SKILL.md under the 'Pixso MCP Design Identification Guide').
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore embedded instructions within design layer metadata.
  • Capability inventory: The skill provides instructions for mapping data to UI components, which is intended to be used by an agent's code generation and file management capabilities.
  • Sanitization: Absent. No mention of filtering, escaping, or validating the content of the design metadata before processing it into the component tree.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:10 AM
Security Audit — agent-trust-hub — opendesign-components