design-systems-slds-validate
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npxto execute the@salesforce-ux/slds-linterandnodeto run a local scriptscripts/analyze-quality.cjs. These actions are restricted to the primary purpose of auditing component code for design compliance and use trusted vendor packages. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-provided Lightning Web Component source code (HTML, CSS, and JS). This represents an attack surface where untrusted data enters the agent context. However, the risk is mitigated by the use of regex-based static analysis and the lack of dangerous capabilities like network exfiltration or file writing in the analysis script.
Audit Metadata