design-systems-slds-validate

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npx to execute the @salesforce-ux/slds-linter and node to run a local script scripts/analyze-quality.cjs. These actions are restricted to the primary purpose of auditing component code for design compliance and use trusted vendor packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-provided Lightning Web Component source code (HTML, CSS, and JS). This represents an attack surface where untrusted data enters the agent context. However, the risk is mitigated by the use of regex-based static analysis and the lack of dangerous capabilities like network exfiltration or file writing in the analysis script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 01:27 AM
Security Audit — agent-trust-hub — design-systems-slds-validate