apple-platform-design

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill references the command npx saglitzdesign-mcp to access the SaglitzDesign Model Context Protocol (MCP) server, which involves downloading and executing code from the npm registry.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the saglitzdesign-mcp package from the official npm registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes tools like compare_design_languages that process external design data, creating a potential surface for indirect prompt injection.
  • Ingestion points: External UI design data processed by the SaglitzDesign MCP tools (SKILL.md).
  • Boundary markers: None identified.
  • Capability inventory: UI analysis and code generation.
  • Sanitization: No specific sanitization or filtering logic is described for the input design data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 06:30 PM
Security Audit — agent-trust-hub — apple-platform-design