apple-platform-design
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill references the command
npx saglitzdesign-mcpto access the SaglitzDesign Model Context Protocol (MCP) server, which involves downloading and executing code from the npm registry. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the
saglitzdesign-mcppackage from the official npm registry. - [INDIRECT_PROMPT_INJECTION]: The skill describes tools like
compare_design_languagesthat process external design data, creating a potential surface for indirect prompt injection. - Ingestion points: External UI design data processed by the SaglitzDesign MCP tools (SKILL.md).
- Boundary markers: None identified.
- Capability inventory: UI analysis and code generation.
- Sanitization: No specific sanitization or filtering logic is described for the input design data.
Audit Metadata