design-to-code

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (design images and Figma metadata) as primary input. It mitigates indirect prompt injection risks by enforcing a mandatory 'Pre-Implementation Brief' that requires human review and confirmation of the implementation plan before the agent generates any code or performs verification steps.- [COMMAND_EXECUTION]: The workflow incorporates automated verification using Playwright to perform screenshot diffs. While this involves shell execution, the process is gated by the initial brief confirmation and is limited to the scope of visual regression testing for the generated UI.- [EXTERNAL_DOWNLOADS]: The skill instructions allow for the retrieval of design assets (SVGs, icons, and images) from platforms like Figma. It explicitly mandates that these assets must be stored locally within the project and forbids the use of remote asset URLs in the final output, reducing reliance on external infrastructure at runtime.- [SAFE]: The skill demonstrates high integrity by including framework-specific resolution logic, explicit stop conditions for ambiguous inputs, and detailed verification steps that ensure output fidelity without compromising the host environment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 12:33 AM