create-styleguide

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in styleguide.py to execute bash scripts for sibling skills (review-design and memory). These calls coordinate design audits and information storage within the local ecosystem.
  • [PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection due to its processing of untrusted data from local files and screenshots.
  • Ingestion points: Reads content from STYLE_GUIDE.md (via debt.py), design token JSON files, and screenshot directories.
  • Boundary markers: No specific delimiters or safety instructions are used when passing extracted data to composed skills or the memory system.
  • Capability inventory: The skill possesses file-writing capabilities and local shell command execution via subprocess.run across several modules.
  • Sanitization: No validation or sanitization is performed on the Markdown or JSON content before it is parsed and used in downstream processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — create-styleguide