opendesign-components
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The instructions require the installation of the
@opensig/opendesignand@opensig/opendesign-tokenpackages from public NPM/PNPM registries. - [PROMPT_INJECTION]: The skill establishes an ingestion surface for indirect prompt injection (Category 8) through its integration with design data.
- Ingestion points: Pixso MCP design node metadata, including layer names, visual attributes, and layout structures (defined in SKILL.md under the 'Pixso MCP Design Identification Guide').
- Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore embedded instructions within design layer metadata.
- Capability inventory: The skill provides instructions for mapping data to UI components, which is intended to be used by an agent's code generation and file management capabilities.
- Sanitization: Absent. No mention of filtering, escaping, or validating the content of the design metadata before processing it into the component tree.
Audit Metadata