frontend-design
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes multiple shell and Python scripts (
init-artifact.sh,bundle-artifact.sh,ux_audit.py) designed to automate project setup, build processes, and design audits. These operations are restricted to the local project environment provided as a path argument.- [EXTERNAL_DOWNLOADS]: The initialization scripts use official package managers (npm, pnpm) to install well-known frontend development dependencies from public registries. It also interacts with official Google APIs via thegoogle-genailibrary for asset generation.- [DATA_EXFILTRATION]: The image generation script (generate_images.py) attempts to read a.env.localfile from the workspace root to retrieve a Gemini API key. This is a standard practice for local development to avoid hardcoding secrets.- [SAFE]: The skill implements a robust 'Selective Reading Rule' and behavioral guidelines to prevent generic AI output, focusing purely on productivity and design principles without attempting to bypass agent safety filters or exfiltrate user data to untrusted third parties.
Audit Metadata