skills/grupous/gpus/frontend-design/Gen Agent Trust Hub

frontend-design

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes multiple shell and Python scripts (init-artifact.sh, bundle-artifact.sh, ux_audit.py) designed to automate project setup, build processes, and design audits. These operations are restricted to the local project environment provided as a path argument.- [EXTERNAL_DOWNLOADS]: The initialization scripts use official package managers (npm, pnpm) to install well-known frontend development dependencies from public registries. It also interacts with official Google APIs via the google-genai library for asset generation.- [DATA_EXFILTRATION]: The image generation script (generate_images.py) attempts to read a .env.local file from the workspace root to retrieve a Gemini API key. This is a standard practice for local development to avoid hardcoding secrets.- [SAFE]: The skill implements a robust 'Selective Reading Rule' and behavioral guidelines to prevent generic AI output, focusing purely on productivity and design principles without attempting to bypass agent safety filters or exfiltrate user data to untrusted third parties.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — frontend-design